{"id":"SUSE-SU-2023:2164-1","summary":"Security update for cloud-init","details":"This update for cloud-init contains following fixes:\n\n - CVE-2021-3429: Do not write the generated password to the log file. (bsc#1184758)\n - CVE-2023-1786: Do not expose sensitive data gathered from the CSP. (bsc#1210277)\n\nOther fixes:\n - Change log file creation mode to 640. (bsc#1183939)\n - Write proper bonding option configuration for SLE/openSUSE. (bsc#1184085)\n - Do not including sudoers.d directory twice. (bsc#1181283)\n","modified":"2026-03-11T07:23:57.914090Z","published":"2023-05-10T17:55:46Z","related":["CVE-2021-3429","CVE-2023-1786"],"upstream":["CVE-2021-3429","CVE-2023-1786"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20232164-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181283"},{"type":"REPORT","url":"https://bugzilla.suse.com/1183939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184758"},{"type":"REPORT","url":"https://bugzilla.suse.com/1210277"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3429"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1786"}],"affected":[{"package":{"name":"cloud-init","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 12","purl":"pkg:rpm/suse/cloud-init&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.2-37.57.1"}]}],"ecosystem_specific":{"binaries":[{"cloud-init-config-suse":"20.2-37.57.1","cloud-init":"20.2-37.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2164-1.json"}}],"schema_version":"1.7.5"}