CVE-2019-0816

medium
Published 2019-07-30 Β· Modified 2019-07-30
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

RHBA-2019:1992: cloud-init bug fix and enhancement update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description cloud-init: extra ssh keys added to authorized_keys on the Azure platform Red Hat statement See steps from https://support.microsoft.com/en-us/help/4491476/extraneous-ssh-public-keys-added-to-authorized-keys-file-on-linux-vm CVSS v3: 5.4 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux…

Description

cloud-init: extra ssh keys added to authorized_keys on the Azure platform

Red Hat statement

See steps from https://support.microsoft.com/en-us/help/4491476/extraneous-ssh-public-keys-added-to-authorized-keys-file-on-linux-vm

CVSS v3: 5.4 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7cloud-init-0:18.2-1.el7_6.2RHSA-2019:05972019-03-18T00:00:00Z
Red Hat Enterprise Linux 8cloud-init-0:18.5-1.el8.4RHBA-2019:19922019-07-30T00:00:00Z

Apply commands

bash fix
Apply RHSA-2019:0597 for Red Hat Enterprise Linux 7
yum update -y cloud-init
# or:
dnf upgrade -y cloud-init

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed18.3-6
debian debianbullseyefixed18.3-6
debian debianforkyfixed18.3-6
debian debiansidfixed18.3-6
debian debiantrixiefixed18.3-6
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.