CVE Vulnerabilities

CVE-2019-0816

Use of Incorrectly-Resolved Name or Reference

Published: Apr 09, 2019 | Modified: Aug 24, 2020
CVSS 3.x
5.1
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka Azure SSH Keypairs Security Feature Bypass Vulnerability.

Weakness

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Ubuntu_linux Canonical 18.04 (including) 18.04 (including)
Red Hat Enterprise Linux 7 RedHat cloud-init-0:18.2-1.el7_6.2 *
Red Hat Enterprise Linux 8 RedHat cloud-init-0:18.5-1.el8.4 *
Cloud-init Ubuntu bionic *
Cloud-init Ubuntu cosmic *
Cloud-init Ubuntu devel *
Cloud-init Ubuntu xenial *

References