CVE-2018-10896
Dashboard / Vulnerabilities / CVE-2018-10896
CVE-2018-10896
Published: 1 Aug 2018Last Modified: 8 Jul 2026
Summary:
Details: The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks.
References: https://bugzilla.redhat.com/show_bug.cgi?id=1574338, https://bugs.launchpad.net/cloud-init/+bug/1781094, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10896
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 2a84a2603f22e5362c8a6620bea51df220245d9f
Affected versions
18.3
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
