VYPR

MaaS

by Ubuntu

CVEs (7)

  • CVE-2014-1427CriApr 22, 2019
    risk 0.62cvss 9.6epss 0.01

    A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue affects MAAS versions prior to 1.9.2.

  • CVE-2014-1426HigApr 22, 2019
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ubuntu MAAS versions prior to 1.9.2.

  • CVE-2025-7044HigDec 3, 2025
    risk 0.50cvss 7.7epss 0.00

    An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing…

  • CVE-2015-1320MedApr 22, 2019
    risk 0.36cvss 5.5epss 0.01

    The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu MAAS versions prior to 1.9.2.

  • CVE-2014-1428LowApr 22, 2019
    risk 0.13cvss 2.0epss 0.01

    A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2.

  • CVE-2013-1070Feb 17, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/.

  • CVE-2013-1069Feb 17, 2014
    risk 0.00cvss epss 0.00

    Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.