Cloud Init
Vendor:
First CVE: Aug 1, 2018 · Active for 7 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cloud Init over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2018
7 years ago
Most Recent CVE
Jun 26, 2025
393 days ago
CVE Severity & Scoring
Cloud Init9 CVEs
67%
33%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local7 (77.8%)
Network1 (11.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (11.1%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (88.9%)
High0 (0.0%)
None1 (11.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6639HIGH An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data. | Nov 25, 2019 | 8.8 | 27 | NO | NO |
CVE-2024-6174HIGH When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform e | Jun 26, 2025 | 8.8 | 24 | NO | NO |
CVE-2018-10896HIGH The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this coul | Aug 1, 2018 | 7.1 | 23 | NO | NO |
CVE-2020-8631MEDIUM cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the | Feb 5, 2020 | 5.5 | 21 | NO | NO |
CVE-2023-1786MEDIUM Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege. | Apr 26, 2023 | 5.5 | 20 | NO | NO |
CVE-2022-2084MEDIUM Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords. | Apr 19, 2023 | 5.5 | 20 | NO | NO |
CVE-2021-3429MEDIUM When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-outpu | Apr 19, 2023 | 5.5 | 20 | NO | NO |
CVE-2024-11584MEDIUM cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used f | Jun 26, 2025 | 5.3 | 17 | NO | NO |
CVE-2020-8632MEDIUM In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords. | Feb 5, 2020 | 5.5 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Cloud Init
Top CWEs
Versions
No cataloged versions.