CVE-2021-3429: sensitive data exposure in cloud-init logs
Published Apr 19, 2023
·Updated
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.
Affected Software
1 affected component
Canonical cloud-init<21.2
Remediation
Event History
Apr 19, 2023
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3429.
2
What is the severity of CVE-2021-3429?
The severity of CVE-2021-3429 is medium with a CVSS score of 5.5.
3
How does CVE-2021-3429 affect the software?
CVE-2021-3429 affects versions before 21.2 of the Canonical Cloud-init software.
4
What is the impact of CVE-2021-3429?
CVE-2021-3429 allows a local user to log in as another user by accessing the world-readable log file.
5
How can I fix CVE-2021-3429?
To fix CVE-2021-3429, you should upgrade to version 21.2 or newer of the Canonical Cloud-init software.