Back

MEDIUM

cloud-init: extra ssh keys added to authorized_keys on the Azure platform

Published Apr 9, 2019

Description

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.

Affected products

Remediation

Red Hat mitigation

See steps from https://support.microsoft.com/en-us/help/4491476/extraneous-ssh-public-keys-added-to-authorized-keys-file-on-linux-vm

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Apr 9, 2019
Updated Aug 4, 2024
Reserved Nov 26, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 5, 2019
ENISA EUVD
Assigner microsoft
Published Apr 9, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-1569