ALAS2-2021-1620

Related Vulnerabilities: CVE-2021-3429  

A vulnerability was discovered in cloud-init which can improperly disclose randomly generated passwords as part of the chpasswd module. The fix prevents the generated password from being written to a world-readable log file on the local disk. (CVE-2021-3429)

ALAS2-2021-1620


Amazon Linux 2 Security Advisory: ALAS-2021-1620
Advisory Release Date: 2021-03-18 18:06 Pacific
Advisory Updated Date: 2021-03-19 22:53 Pacific
Severity: Medium
References: CVE-2021-3429 

Issue Overview:

A vulnerability was discovered in cloud-init which can improperly disclose randomly generated passwords as part of the chpasswd module. The fix prevents the generated password from being written to a world-readable log file on the local disk. (CVE-2021-3429)


Affected Packages:

cloud-init


Issue Correction:
Run yum update cloud-init to update your system.

New Packages:
noarch:
    cloud-init-19.3-43.amzn2.noarch

src:
    cloud-init-19.3-43.amzn2.src