Medium severity5.5NVD Advisory· Published Feb 5, 2020· Updated Jun 17, 2026
CVE-2020-8632
CVE-2020-8632
Description
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- cloud-init/cloud-initdescription
- Range: <=19.4
- osv-coords5 versionspkg:rpm/opensuse/cloud-init&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cloud-init&distro=openSUSE%20Tumbleweedpkg:rpm/suse/cloud-init&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012pkg:rpm/suse/cloud-init&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015pkg:rpm/suse/cloud-init&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP1
< 19.4-lp151.2.15.1+ 4 more
- (no CPE)range: < 19.4-lp151.2.15.1
- (no CPE)range: < 21.2-1.2
- (no CPE)range: < 19.4-37.39.1
- (no CPE)range: < 19.4-5.24.1
- (no CPE)range: < 19.4-8.17.1
Patches
Vulnerability mechanics
References
4- bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795nvdIssue TrackingPatchThird Party Advisory
- github.com/canonical/cloud-init/pull/189nvdPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00042.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/02/msg00021.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.