CVE Vulnerabilities

CVE-2012-6639

Improper Privilege Management

Published: Nov 25, 2019 | Modified: Aug 18, 2020
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
7.1 IMPORTANT
AV:N/AC:H/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
LOW

An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Cloud-init Canonical * 0.7.0 (excluding)
Cloud-init Ubuntu lucid *
Cloud-init Ubuntu precise *

Potential Mitigations

References