Updated cloud-init packages fix security vulnerabilityPublication date: 31 Jul 2020
Affected Mageia releases : 7
CVE: CVE-2020-8631 , CVE-2020-8632
In cloud-init, relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function (CVE-2020-8631). In cloud-init, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords (CVE-2020-8632).