Inclusion of Sensitive Information in Log Files in cloud-init (Ubuntu package) - CVE-2021-3429
Published: March 23, 2021
Vulnerability identifier: #VU51629
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3429
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to cloud-init writes randomly generated passwords as part of the chpasswd module into log files. A local user can read the log files and gain access to sensitive data.
Affected software
cloud-init (Ubuntu package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
cloud-init (Red Hat package)
cloud-init
cloud-init-help
cloud-init-config-suse
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openEuler
NetWorker
NetWorker Management Console
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
cloud-init (Red Hat package)
cloud-init
cloud-init-help
cloud-init-config-suse
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openEuler
NetWorker
NetWorker Management Console
How to mitigate CVE-2021-3429
Install updates from vendor's website.
cloud-init (Red Hat package) - addressed in versions 18.5-7.el8_1.6, 18.5-12.el8_2.10, 20.3-10.el8_4.5
cloud-init - addressed in versions 18.5-12.0.1, 20.3-10.0.1
cloud-init - update to 19.4-5
cloud-init-help - update to 19.4-5
NetWorker - addressed in versions 19.11.0.3, 19.12.0.0
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
cloud-init - update to 20.2-37.57.1
cloud-init-config-suse - update to 20.2-37.57.1
cloud-init - addressed in versions 18.5-12.0.1, 20.3-10.0.1
cloud-init - update to 19.4-5
cloud-init-help - update to 19.4-5
NetWorker - addressed in versions 19.11.0.3, 19.12.0.0
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
cloud-init - update to 20.2-37.57.1
cloud-init-config-suse - update to 20.2-37.57.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Canonical cloud-init
- Amazon Linux AMI update for cloud-init
- Red Hat Enterprise Linux 8.4 update for cloud-init
- Red Hat Enterprise Linux 8.1 update for cloud-init
- Red Hat Enterprise Linux 8.2 update for cloud-init
- SUSE update for cloud-init
- openEuler update for cloud-init
- Anolis OS update for cloud-init (Anolis OS 8.4)
- Anolis OS update for cloud-init (Anolis OS 8.2)
- Multiple vulnerabilities in Dell NetWorker and NetWorker Management Console