A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka Azure SSH Keypairs Security Feature Bypass Vulnerability.
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_linux | Canonical | 18.04 (including) | 18.04 (including) |
Red Hat Enterprise Linux 7 | RedHat | cloud-init-0:18.2-1.el7_6.2 | * |
Red Hat Enterprise Linux 8 | RedHat | cloud-init-0:18.5-1.el8.4 | * |
Cloud-init | Ubuntu | bionic | * |
Cloud-init | Ubuntu | cosmic | * |
Cloud-init | Ubuntu | devel | * |
Cloud-init | Ubuntu | xenial | * |