VYPR

rpm package

almalinux/cloud-init

pkg:rpm/almalinux/cloud-init

Vulnerabilities (2)

  • CVE-2024-6174Jun 26, 2025
    affected < 24.4-3.el10_0.2fixed 24.4-3.el10_0.2

    When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

  • CVE-2023-1786Apr 26, 2023
    affected < 23.1.1-11.el9.alma.1fixed 23.1.1-11.el9.alma.1

    Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.