PT-2019-1600 · Canonical+3 · Cloud-Init+3

Published

2019-03-05

·

Updated

2024-06-15

·

CVE-2019-0816

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions cloud-init (affected versions not specified)
Description The issue is related to an error in processing user-controlled authorization keys, which can be exploited by a remote attacker to gain unauthorized access to protected information. A security feature bypass exists due to a change in the provisioning logic for some Linux images that use cloud-init.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01142
CESA-2019_0597
CVE-2019-0816
OPENSUSE-SU-2019:2633-1
OPENSUSE-SU-2019_2633-1
OPENSUSE-SU-2024:10688-1
RHSA-2019:0597
RHSA-2019_0597
SUSE-SU-2019:3096-1
SUSE-SU-2019:3097-1
SUSE-SU-2019:3191-1
SUSE-SU-2019_3096-1
SUSE-SU-2019_3097-1
SUSE-SU-2019_3191-1

Affected Products

Centos
Red Hat
Suse
Cloud-Init