Inclusion of Sensitive Information in Log Files in cloud-init (Ubuntu package) - CVE-2021-3429

 

Inclusion of Sensitive Information in Log Files in cloud-init (Ubuntu package) - CVE-2021-3429

Published: March 23, 2021


Vulnerability identifier: #VU51629
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3429
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to cloud-init writes randomly generated passwords as part of the chpasswd module into log files. A local user can read the log files and gain access to sensitive data.


Affected software

cloud-init (Ubuntu package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
cloud-init (Red Hat package)
cloud-init
cloud-init-help
cloud-init-config-suse
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openEuler
NetWorker
NetWorker Management Console

How to mitigate CVE-2021-3429

Install updates from vendor's website.

cloud-init (Red Hat package) - addressed in versions 18.5-7.el8_1.6, 18.5-12.el8_2.10, 20.3-10.el8_4.5
cloud-init - addressed in versions 18.5-12.0.1, 20.3-10.0.1
cloud-init - update to 19.4-5
cloud-init-help - update to 19.4-5
NetWorker - addressed in versions 19.11.0.3, 19.12.0.0
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
cloud-init - update to 20.2-37.57.1
cloud-init-config-suse - update to 20.2-37.57.1

External References

Related Security Bulletins