In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795 | issue tracking third party advisory patch |
https://github.com/canonical/cloud-init/pull/189 | third party advisory patch |
https://lists.debian.org/debian-lts-announce/2020/02/msg00021.html | third party advisory mailing list |
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00042.html | mailing list third party advisory vendor advisory |