ALINUX2-SA-2020%3A0167
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-10896: The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks. CVE-2020-8631: cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function. CVE-2020-8632: In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | cloud-init |
Timeline
- Oct 16, 2020 CVE Published
- Oct 16, 2020 CVE Updated
References
- ALINUX2-SA-2020:0167: cloud-init security, bug fix, and enhancement update (Moderate) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10896 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8631 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8632 advisory