Vulnerabilities
Vulnerable Software
Canonical:  >> Cloud-Init  >> 23.3.3  Security Vulnerabilities
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
CVSS Score
8.8
EPSS Score
0.0
Published
2025-06-26
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
CVSS Score
5.9
EPSS Score
0.0
Published
2025-06-26


Contact Us

Shodan ® - All rights reserved