VendorsCanonicalcloud-initall versions
Vulnerabilities

Canonical Cloud-init

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2012-6639
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
Published 2019-11-25 · Modified
9.0EPSS 0.020
CVE-2024-6174
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
Published 2025-06-26 · Analyzed
8.8EPSS 0.002
CVE-2018-10896
The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks.
Published 2018-08-01 · Modified
7.1EPSS 0.004
CVE-2024-11584
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
Published 2025-06-26 · Analyzed
5.9EPSS 0.001
CVE-2020-8631
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
Published 2020-02-05 · Modified
5.5EPSS 0.004
CVE-2020-8632
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
Published 2020-02-05 · Modified
5.5EPSS 0.004
CVE-2023-1786
sensitive data exposure in cloud-init logs
Published 2023-04-26 · Modified
5.5EPSS 0.003
CVE-2022-2084
sensitive data exposure in cloud-init logs
Published 2023-04-19 · Modified
5.5EPSS 0.002
CVE-2021-3429
sensitive data exposure in cloud-init logs
Published 2023-04-19 · Modified
5.5EPSS 0.002