Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://github.com/canonical/cloud-init/commit/4d467b14363d800b2185b89790d57871f11ea88c | patch |
https://ubuntu.com/security/notices/USN-5496-1 | vendor advisory broken link |