Information disclosure in cloud-init (Ubuntu package) - CVE-2023-1786

 

Information disclosure in cloud-init (Ubuntu package) - CVE-2023-1786

Published: April 27, 2023


Vulnerability identifier: #VU75538
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-1786
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

cloud-init (Ubuntu package)
cloud-init
cloud-init-help
cloud-init-config-suse
cloud-init (Red Hat package)
cloud-init-doc
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Ubuntu
openEuler
Anolis OS
Fedora
Juniper Secure Analytics (JSA)
VMware Tanzu Operations Manager
IBM Qradar SIEM
NetWorker Management Console
NetWorker

How to mitigate CVE-2023-1786

Install updates from vendor's website.

cloud-init (Ubuntu package) - addressed in versions 23.1.2, Ubuntu Pro, 23.1.2-0ubuntu0~18.04.1, 23.1.2-0ubuntu0~20.04.1, 23.1.2-0ubuntu0~22.04.1, 23.1.2-0ubuntu0~22.10.1, 23.1.2-0ubuntu0~23.04.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
VMware Tanzu Operations Manager - addressed in versions 2.7.24, 2.8.14, 2.9.11, 2.10.57, 3.0.8
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
cloud-init - update to 19.4-11
cloud-init-help - update to 19.4-11
NetWorker - addressed in versions 19.11.0.3, 19.12.0.0
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
cloud-init-config-suse - addressed in versions 20.2-37.57.1, 23.1-150100.8.63.5, 23.3-150100.8.71.1
cloud-init - addressed in versions 20.2-37.57.1, 23.1-150100.8.63.5, 23.3-150100.8.71.1
cloud-init - update to 22.2.2-1
cloud-init (Red Hat package) - addressed in versions 23.1.1-10.el8, 23.1.1-11.el9
cloud-init - update to 23.1.2-1.fc38
cloud-init-doc - addressed in versions 23.1-150100.8.63.5, 23.3-150100.8.71.1
cloud-init - update to 23.2.2-1

External References

Related Security Bulletins