CVE-2020-8632: Medium severity Canonical cloud-init vulnerability
In cloud-init through 19.4, randuserpassword in cloudinit/config/ccsetpasswords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-8632.
What is the title of the vulnerability?
The title of the vulnerability is 'In cloud-init through 19.4 rand_user_password in cloudinit/config/cc_set_passwords.py has a small de…'.
What is the description of the vulnerability?
The vulnerability allows attackers to guess passwords more easily due to a small default pwlen value in cloud-init.
Which software versions are affected by the vulnerability?
Canonical Cloud-init version up to and including 19.4, openSUSE Leap version 15.1, and Debian Debian Linux version 8.0 are affected by the vulnerability.
What is the severity of CVE-2020-8632?
The severity of CVE-2020-8632 is medium with a CVSS score of 5.5.
How can I fix the vulnerability?
To fix the vulnerability, update your cloud-init software to a version that includes the patch.