In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
2020-02-05T14:15:11.653
2024-11-21T05:39:09.433
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | canonical | cloud-init | ≤ 19.4 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |