rpm package
suse/cloud-init&distro=SUSE Linux Micro 6.1
pkg:rpm/suse/cloud-init&distro=SUSE%20Linux%20Micro%206.1
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-11584 | — | < 25.1.3-slfo.1.1_1.1 | 25.1.3-slfo.1.1_1.1 | Jun 26, 2025 | cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook comm | ||
| CVE-2024-6174 | — | < 25.1.3-slfo.1.1_1.1 | 25.1.3-slfo.1.1_1.1 | Jun 26, 2025 | When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration. | ||
| CVE-2023-1786 | — | < 25.1.3-slfo.1.1_1.1 | 25.1.3-slfo.1.1_1.1 | Apr 26, 2023 | Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege. |
- CVE-2024-11584Jun 26, 2025affected < 25.1.3-slfo.1.1_1.1fixed 25.1.3-slfo.1.1_1.1
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook comm
- CVE-2024-6174Jun 26, 2025affected < 25.1.3-slfo.1.1_1.1fixed 25.1.3-slfo.1.1_1.1
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
- CVE-2023-1786Apr 26, 2023affected < 25.1.3-slfo.1.1_1.1fixed 25.1.3-slfo.1.1_1.1
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.