VYPR

rpm package

opensuse/cloud-init&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/cloud-init&distro=openSUSE%20Leap%2016.0

Vulnerabilities (2)

  • CVE-2024-6174HigJun 26, 2025
    affected < 25.1.3-160000.2.1fixed 25.1.3-160000.2.1

    When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

  • CVE-2024-11584MedJun 26, 2025
    affected < 25.1.3-160000.2.1fixed 25.1.3-160000.2.1

    cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook comm