VDB
GCVE-110-MAGEIA-2020-295
GCVE-110-MAGEIA-2020-295
Advisory Published
In cloud-init, relies on Mersenne Twister for a random password, which
makes it easier for attackers to predict passwords, because rand_str in
cloudinit/util.py calls the random.choice function (CVE-2020-8631).
In cloud-init, rand_user_password in cloudinit/config/cc_set_passwords.py
has a small default pwlen value, which makes it easier for attackers to
guess passwords (CVE-2020-8632).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | cloud-init | 0 (affected), 0.7.5-7.1.mga7 (unaffected) | — |
Browse GCVE Records
76,019 records in the GCVE database · Updated August 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.