CVE Vulnerabilities

CVE-2021-3429

Insertion of Sensitive Information into Log File

Published: Apr 19, 2023 | Modified: Feb 05, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
Cloud-initCanonical*21.2 (excluding)
Red Hat Enterprise Linux 8RedHatcloud-init-0:20.3-10.el8_4.5*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatcloud-init-0:18.5-7.el8_1.6*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatcloud-init-0:18.5-12.el8_2.10*
Cloud-initUbuntubionic*
Cloud-initUbuntuesm-infra/bionic*
Cloud-initUbuntuesm-infra/focal*
Cloud-initUbuntuesm-infra/xenial*
Cloud-initUbuntufocal*
Cloud-initUbuntugroovy*
Cloud-initUbuntutrusty*
Cloud-initUbuntuupstream*
Cloud-initUbuntuxenial*

Potential Mitigations

References