Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
2023-04-19T22:15:10.207
2025-02-05T15:15:15.360
Modified
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | canonical | cloud-init | < 22.3 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 20.04 | Yes |
Operating System | canonical | ubuntu_linux | 21.10 | Yes |
Operating System | canonical | ubuntu_linux | 22.04 | Yes |