CVE-2022-2084: sensitive data exposure in cloud-init logs
Last updated 24 July 2024
Other sources
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
— Launchpad
Affected Software
Remediation
Mitigation
Event History
Frequently Asked Questions
What is CVE-2022-2084?
CVE-2022-2084 is a vulnerability that could expose sensitive data in world-readable logs of cloud-init before version 22.3 when schema failures are reported.
What is the severity of CVE-2022-2084?
The severity of CVE-2022-2084 is medium with a severity value of 5.5.
Which software versions are affected by CVE-2022-2084?
The vulnerability affects cloud-init versions before 22.3 and Canonical Ubuntu Linux 18.04, 20.04, 21.10, and 22.04.
How can I fix CVE-2022-2084?
To fix CVE-2022-2084, update your cloud-init software to version 22.3 or above.
Where can I find more information about CVE-2022-2084?
You can find more information about CVE-2022-2084 at the following references: [reference 1](https://github.com/canonical/cloud-init/commit/4d467b14363d800b2185b89790d57871f11ea88c), [reference 2](https://ubuntu.com/security/notices/USN-5496-1), [reference 3](https://launchpad.net/bugs/cve/CVE-2022-2084).