Bug#951362: cloud-init: CVE-2020-8631
Tags: security upstream
The following vulnerability was published for cloud-init.
| cloud-init through 19.4 relies on Mersenne Twister for a random
| password, which makes it easier for attackers to predict passwords,
| because rand_str in cloudinit/util.py calls the random.choice
AFAIU not yet fixed upstream.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
Please adjust the affected versions in the BTS as needed.