Known vulnerabilities in cloud-init (Ubuntu package)

Software CPE: cpe:2.3:o:canonical:cloud-init_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Total vulnerabilities: 7
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting cloud-init (Ubuntu package) cloud-init (Ubuntu package) is affected by 7 known vulnerabilities: 1 high, 1 medium, 5 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU112884 - Insufficient Verification of Data Authenticity
CVE-2024-6174
CWE-345 High
No
No
21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2, 23.1.2-0ubuntu0~18.04.1+esm1, 24.4.1-0ubuntu0~20.04.3+esm1, 25.1.4-0ubuntu0~22.04.1, 25.1.4-0ubuntu0~24.04.1, 25.1.4-0ubuntu0~25.04.1 14.07.2025 SB2025071434
SB2025071437
SB2025071438
and 18 more
#VU112883 - Incorrect Default Permissions
CVE-2024-11584
CWE-276 Low
No
No
21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2, 23.1.2-0ubuntu0~18.04.1+esm1, 24.4.1-0ubuntu0~20.04.3+esm1, 25.1.4-0ubuntu0~22.04.1, 25.1.4-0ubuntu0~24.04.1, 25.1.4-0ubuntu0~25.04.1 14.07.2025 SB2025071434
SB2025071437
SB2025071438
and 10 more
#VU75538 - Exposure of sensitive information to an unauthorized actor
CVE-2023-1786
CWE-200 Medium
No
No
23.1.2, Ubuntu Pro, 23.1.2-0ubuntu0~18.04.1, 23.1.2-0ubuntu0~20.04.1, 23.1.2-0ubuntu0~22.04.1, 23.1.2-0ubuntu0~22.10.1, 23.1.2-0ubuntu0~23.04.1 27.04.2023 SB2023042703
SB2023042706
SB2023051101
and 16 more
#VU64838 - Information Exposure Through Log Files
CVE-2022-2084
CWE-532 Low
No
No
22.2-0ubuntu1~18.04.3, 22.2-0ubuntu1~20.04.3, 22.2-0ubuntu1~21.10.3, 22.2-0ubuntu1~22.04.3 30.06.2022 SB2022063026
SB2023062401
SB2023051967
and 3 more
#VU51629 - Information Exposure Through Log Files
CVE-2021-3429
CWE-532 Low
No
No
- 23.03.2021 SB2021032302
SB2021032303
SB2021081120
and 7 more
#VU51628 - Insufficiently Protected Credentials
CVE-2020-8632
CWE-522 Low
No
No
20.1 23.03.2021 SB2021032302
SB2021032303
SB2020110440
and 1 more
#VU51627 - Use of Insufficiently Random Values
CVE-2020-8631
CWE-330 Low
No
No
20.1 23.03.2021 SB2021032302
SB2021032303
SB2020110440
and 1 more