VYPR

MAAS

by Maas

CVEs (4)

  • CVE-2026-14450CriAug 10, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication…

  • CVE-2024-6107CriJul 21, 2025
    risk 0.62cvss 9.6epss 0.00

    Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.

  • CVE-2025-7044HigDec 3, 2025
    risk 0.50cvss 7.7epss 0.00

    An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing…

  • CVE-2013-1057Nov 18, 2013
    risk 0.00cvss epss 0.01

    Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current working directory.