Harry Sintonen discovered that the hotplugd socket in cloud-init was world writable. An attacker could possibly use this issue to send hotplug-hook commands. (CVE-2024-11584)
It was discovered that cloud-init granted root access to a hardcoded URL with a local IP address when a non-x86 platform is detected. An attacker could possibly impersonate an OpenStack endpoint and provide root configuration data. (CVE-2024-6174)
{ "binaries": [ { "binary_version": "21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2", "binary_name": "cloud-init" }, { "binary_version": "21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2", "binary_name": "ec2-init" }, { "binary_version": "21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2", "binary_name": "grub-legacy-ec2" } ], "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
{ "binaries": [ { "binary_version": "25.1.4-0ubuntu0~25.04.1", "binary_name": "cloud-init" }, { "binary_version": "25.1.4-0ubuntu0~25.04.1", "binary_name": "cloud-init-base" }, { "binary_version": "25.1.4-0ubuntu0~25.04.1", "binary_name": "cloud-init-cloud-sigma" }, { "binary_version": "25.1.4-0ubuntu0~25.04.1", "binary_name": "cloud-init-smart-os" } ], "availability": "No subscription required" }