Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
sensitive data exposure in cloud-init logs
Vulnerability Description
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
Cloud-init 日志信息泄露漏洞
Vulnerability Description
Cloud-init是一款用于云平台的虚拟机初始化工具。 Cloud-init 存在日志信息泄露漏洞,攻击者可利用该漏洞可以通过非散列生成的cloud-init密码绕过限制,以升级他的特权。
CVSS Information
N/A
Vulnerability Type
N/A