First published: Wed Feb 05 2020(Updated: )
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
cloud-init | <=19.4 | |
openSUSE | =15.1 | |
Debian | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-8632.
The title of the vulnerability is 'In cloud-init through 19.4 rand_user_password in cloudinit/config/cc_set_passwords.py has a small de…'.
The vulnerability allows attackers to guess passwords more easily due to a small default pwlen value in cloud-init.
Canonical Cloud-init version up to and including 19.4, openSUSE Leap version 15.1, and Debian Debian Linux version 8.0 are affected by the vulnerability.
The severity of CVE-2020-8632 is medium with a CVSS score of 5.5.
To fix the vulnerability, update your cloud-init software to a version that includes the patch.