VDB

GCVE-110-MAGEIA-2020-295

GCVE-110-MAGEIA-2020-295
Advisory Published
Vulnetix · Advisory published July 31, 2020
In cloud-init, relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function (CVE-2020-8631). In cloud-init, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords (CVE-2020-8632).

Affected Products

VendorProductVersionsPlatforms
Mageiacloud-init0 (affected), 0.7.5-7.1.mga7 (unaffected)

Browse GCVE Records

76,019 records in the GCVE database · Updated August 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›