An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
| Software | From | Fixed in |
|---|---|---|
| canonical / cloud-init | - | 0.7.0 |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |
| suse / linux_enterprise_server | 11-sp2 | 11-sp2.x |
| suse / linux_enterprise_server | 11-sp3 | 11-sp3.x |