MEDIUM
cloud-init: extra ssh keys added to authorized_keys on the Azure platform
Published Apr 9, 2019
5.4
MEDIUMCVSS 3.0
EPSS 1.40%
Description
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.
Affected products
-
- Version 18.04-LTSStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Ubuntu Server | n/a |
|
AND
- 18.04
No data.
Red Hat Enterprise Linux 7
cloud-init-0:18.2-1.el7_6.2
Fixed · RHSA-2019:0597
Red Hat Enterprise Linux 8
cloud-init-0:18.5-1.el8.4
Fixed · RHBA-2019:1992
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | cloud-init-0:18.2-1.el7_6.2 | Fixed | RHSA-2019:0597 |
| Red Hat Enterprise Linux 8 | cloud-init-0:18.5-1.el8.4 | Fixed | RHBA-2019:1992 |
No package ranges for this CVE.
Remediation
Red Hat mitigation
See steps from https://support.microsoft.com/en-us/help/4491476/extraneous-ssh-public-keys-added-to-authorized-keys-file-on-linux-vm
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00018.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2019-0816 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1680165 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-1569 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-0816
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0816 x_refsource_CONFIRMVendor Advisory
- https://support.microsoft.com/en-us/help/4491476/extraneous-ssh-public-keys-added-to-authorized-keys-file-on-linux-vm
- https://www.cve.org/CVERecord?id=CVE-2019-0816
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Apr 9, 2019
Updated Aug 4, 2024
Reserved Nov 26, 2018
Link CVE-2019-0816
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-1569 Assigner microsoft
Published Apr 9, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2019-1569