VDB

ALINUX2-SA-2020%3A0167

ALINUX2-SA-2020%3A0167 PUBLISHED CVSS 4.599999904632568 MEDIUM

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-10896: The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks. CVE-2020-8631: cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function. CVE-2020-8632: In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.

Risk Scores

CVSS 3.0
4.599999904632568
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Alibaba Cloudcloud-init

Timeline

  • Oct 16, 2020 CVE Published
  • Oct 16, 2020 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›