---
title: "CVE-2018-15869\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2018-15869?format=md
keywords: index, follow
---

# CVE-2018-15869

Publication date 25 August 2018

Last updated 11 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2018-15869?format=md#impact-score)

Toggle side navigation

## Description

An Amazon Web Services (AWS) developer who does not specify the --owners
flag when describing images via AWS CLI, and therefore not properly
validating source software per AWS recommended security best practices, may
unintentionally load an undesired and potentially malicious Amazon Machine
Image (AMI) from the uncurated public community AMI catalog.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2018-15869?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| awscli | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Not in release |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| packer | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 23.10 mantic | Not in release |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Ignored end of life, was needed |
| 22.04 LTS jammy | Vulnerable |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Vulnerable |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.10 cosmic | Ignored end of life |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2018-15869?format=md#patch-details)

## Notes

---

### [msalvatore](https://launchpad.net/~msalvatore)

This CVE may actually be against hashicorp/packer instead of
awscli. Monitor https://github.com/hashicorp/packer/issues/6584
to see if this actually affects awscli.

---

### [redhat](https://launchpad.net/~redhat)

Closing this bug as NOTABUG and asked MITRE for rejection, since the
issue does not seem to be in AWS CLI but in Packer.

---

### [msalvatore](https://launchpad.net/~msalvatore)

Amazon has addressed this: "The ability to query for images without
specifying an owner is the intended design." "This seems to have
been a gap in 3rd party software"
Ignoring awscli package.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| awscli | * Upstream:   <https://github.com/hashicorp/packer/pull/6585/commits/250da0ab49d9f4a15a024dcd550537c3f187ad8e> * Upstream:   <https://github.com/hashicorp/packer/pull/6585/commits/71cad4f2a91b67dd150264cc13f674035016e7fb> * Upstream:   <https://github.com/hashicorp/packer/pull/6585/commits/d57b599f3c83721750bc78ca58f862ffb840bf0a> * Upstream:   <https://github.com/hashicorp/packer/pull/6694/commits/d5ce18b857afe6e6850e10324a57f8427b961a65> |
| packer | * Upstream:   <https://github.com/hashicorp/packer/pull/6585/commits/250da0ab49d9f4a15a024dcd550537c3f187ad8e> * Upstream:   <https://github.com/hashicorp/packer/pull/6585/commits/71cad4f2a91b67dd150264cc13f674035016e7fb> * Upstream:   <https://github.com/hashicorp/packer/pull/6585/commits/d57b599f3c83721750bc78ca58f862ffb840bf0a> * Upstream:   <https://github.com/hashicorp/packer/pull/6694/commits/d5ce18b857afe6e6850e10324a57f8427b961a65> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | Low |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15869)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-15869)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2018-15869)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2018-15869)

### Other references

* <https://github.com/hashicorp/packer/issues/6584>
* <https://github.com/aws/aws-cli/issues/3629>
* <https://www.cve.org/CVERecord?id=CVE-2018-15869>
