CVE-2018-10896
cloud-init: default configuration disabled deletion of SSH host keys
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks.
La configuración por defecto en cloud-init, en versiones a partir de la 0.6.2, incluía "ssh_deletekeys: 0", deshabilitando la eliminación de cloud-init de claves de host ssh. En algunos entornos, esto podría conducir a que se creen instancias creadas al clonar un sistema golden master o template, a que se compartan claves de host ssh o a que se pueda suplantar a otro o llevar a cabo ataques de Man-in-the-Middle (MitM).
The default cloud-init configuration included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks.
The cloud-init packages provide a set of init scripts for cloud instances. Cloud instances need special scripts to run during initialization to retrieve and install SSH keys, and to let the user run various scripts.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-09 CVE Reserved
- 2018-08-01 CVE Published
- 2024-08-05 CVE Updated
- 2025-07-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-321: Use of Hard-coded Cryptographic Key
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1574338 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugs.launchpad.net/cloud-init/+bug/1781094 | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10896 | 2023-02-13 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2018-10896 | 2020-09-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1598831 | 2020-09-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Canonical Search vendor "Canonical" | Cloud-init Search vendor "Canonical" for product "Cloud-init" | >= 0.6.2 < 18.4 Search vendor "Canonical" for product "Cloud-init" and version " >= 0.6.2 < 18.4" | - |
Affected
|