NA

CVE-2023-1786

Published: 26/04/2023 Updated: 08/05/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 20.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 22.04

canonical ubuntu linux 22.10

canonical ubuntu linux 23.04

canonical cloud-init

fedoraproject fedora 38

Vendor Advisories

Synopsis Moderate: cloud-init security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for cloud-init is now available for Red Hat Enterprise Linux 9Red Hat Product Security has ...
Debian Bug report logs - #1035023 cloud-init: CVE-2023-1786 Package: src:cloud-init; Maintainer for src:cloud-init is Debian Cloud Team <debian-cloud@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 27 Apr 2023 19:33:02 UTC Severity: important Tags: security, upstream Found in vers ...
DescriptionThe MITRE CVE dictionary describes this issue as: Sensitive data could be exposed in logs of cloud-init before version 2312 An attacker could use this information to find hashed passwords and possibly escalate their privilege ...