Back to search
CVE-2020-8631
Published: Feb 5, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/canonical/cloud-init/pull/204
x_refsource_MISC
[debian-lts-announce] 20200221 [SECURITY] [DLA 2113-1] cloud-init security update
mailing-list
x_refsource_MLIST
openSUSE-SU-2020:0400
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now