CVE Vulnerabilities

CVE-2023-1786

Insertion of Sensitive Information into Log File

Published: Apr 26, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
Cloud-initCanonical*23.1.2 (excluding)
Ubuntu_linuxCanonical16.04 (including)16.04 (including)
Ubuntu_linuxCanonical18.04 (including)18.04 (including)
Ubuntu_linuxCanonical20.04 (including)20.04 (including)
Ubuntu_linuxCanonical22.04 (including)22.04 (including)
Ubuntu_linuxCanonical22.10 (including)22.10 (including)
Ubuntu_linuxCanonical23.04 (including)23.04 (including)
Red Hat Enterprise Linux 8RedHatcloud-init-0:23.1.1-10.el8*
Red Hat Enterprise Linux 9RedHatcloud-init-0:23.1.1-11.el9*
Cloud-initUbuntubionic*
Cloud-initUbuntuesm-infra/bionic*
Cloud-initUbuntuesm-infra/focal*
Cloud-initUbuntuesm-infra/xenial*
Cloud-initUbuntufocal*
Cloud-initUbuntujammy*
Cloud-initUbuntukinetic*
Cloud-initUbuntulunar*
Cloud-initUbuntutrusty*
Cloud-initUbuntuupstream*
Cloud-initUbuntuxenial*

Potential Mitigations

References