Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-1786

Published: August 31, 2023Last modified: August 31, 2023

Description

Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita LinuxStreamcloud-initNot affected (23.2.2-r0)

References

ON THIS PAGE