Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-3429
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
sensitive data exposure in cloud-init logs
Source: NVD (National Vulnerability Database)
Vulnerability Description
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
通过日志文件的信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cloud-init 日志信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cloud-init是一款用于云平台的虚拟机初始化工具。 Cloud-init 存在日志信息泄露漏洞,攻击者可利用该漏洞可以通过非散列生成的cloud-init密码绕过限制,以升级他的特权。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Canonical Ltd.cloud-init 0 ~ 21.2 -
II. Public POCs for CVE-2021-3429
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-3429
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-3429

No comments yet


Leave a comment