← Back to CVE List

CVE-2021-3429

Published: 2023-04-19T22:15Z
Last Modified: 2025-02-05T15:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt