PT-2019-1600 · Canonical+3 · Cloud-Init+3

Publicado

2019-03-05

·

Atualizado

2024-06-15

·

CVE-2019-0816

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions cloud-init (affected versions not specified)
Description The issue is related to an error in processing user-controlled authorization keys, which can be exploited by a remote attacker to gain unauthorized access to protected information. A security feature bypass exists due to a change in the provisioning logic for some Linux images that use cloud-init.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01142
CESA-2019_0597
CVE-2019-0816
OPENSUSE-SU-2019:2633-1
OPENSUSE-SU-2019_2633-1
OPENSUSE-SU-2024:10688-1
RHSA-2019:0597
RHSA-2019_0597
SUSE-SU-2019:3096-1
SUSE-SU-2019:3097-1
SUSE-SU-2019:3191-1
SUSE-SU-2019_3096-1
SUSE-SU-2019_3097-1
SUSE-SU-2019_3191-1

Produtos afetados

Centos
Red Hat
Suse
Cloud-Init