Red Hat Bugzilla – Bug 1598831
CVE-2018-10896 cloud-init: default configuration disabled deletion of SSH host keys
Last modified: 2018-08-06 20:59:01 EDT
A flaw was found in cloud-init. SSH host keys are not regenerated when new VM instances are created in combination with hashicorp packer and cloud-init. This could lead to the Man In The Middle (MITM) attack. References: https://bugzilla.redhat.com/show_bug.cgi?id=1574338
Created cloud-init tracking bugs for this issue: Affects: epel-6 [bug 1598833] Affects: fedora-all [bug 1598832]
Reported upstream: https://bugs.launchpad.net/cloud-init/+bug/1781094
Upstream commit now merged to master: https://git.launchpad.net/cloud-init/commit/?id=e218c597