Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cloud-init 安全特征问题漏洞
Vulnerability Description
Cloud-init是一款用于云平台的虚拟机初始化工具。 Cloud-init 19.4及之前版本中存在安全特征问题漏洞,该漏洞源于cloudinit/util.py文件中的rand_str调用了‘random.choice’函数。攻击者可利用该漏洞猜测出密码。
CVSS Information
N/A
Vulnerability Type
N/A