Bug 2190079 (CVE-2023-1786)

Summary: CVE-2023-1786 cloud-init: sensitive data could be exposed in logs
Product: [Other] Security Response Reporter: Sandipan Roy <saroy>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: andavis, bdas, ddepaula, huzhao, jferlan, jgreguske, nobody, virt-maint, xiliang, yacao
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in cloud-init. With this flaw, exposure of sensitive data is possible in world-readable cloud-init logs. This flaw allows an attacker to use this information to find hashed passwords and possibly escalate their privilege.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2190081, 2190082, 2190083    
Bug Blocks: 2190077    

Description Sandipan Roy 2023-04-27 05:31:52 UTC
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.

https://bugs.launchpad.net/cloud-init/+bug/2013967
https://ubuntu.com/security/notices/USN-6042-1
https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813f6fe0a6b

Comment 1 Sandipan Roy 2023-04-27 05:38:27 UTC
Created cloud-init tracking bugs for this issue:

Affects: fedora-all [bug 2190082]

Comment 4 errata-xmlrpc 2023-11-07 08:14:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:6371 https://access.redhat.com/errata/RHSA-2023:6371

Comment 5 errata-xmlrpc 2023-11-14 15:17:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:6943 https://access.redhat.com/errata/RHSA-2023:6943