Back

HIGH

cloud-init: insecure transmission of EC2 instance data can lead to root privilege escalation

Published Nov 25, 2019

Description

An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of cloud-init as shipped with Red Hat Enterprise Linux OpenStack Platform 3.0.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 25, 2019
Updated Aug 6, 2024
Reserved Mar 6, 2014
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jan 7, 2014