VendorsCanonicalmetal_as_a_serviceany version
Vulnerabilities

Canonical Metal as a Service (MAAS) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2015-1320
Probe-and-enlist for SeaMicro chassis writes password to the log
Published 2019-04-22 · Modified
9.8EPSS 0.009
CVE-2024-6107
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
Published 2025-07-21 · Analyzed
9.8EPSS 0.004
CVE-2014-1427
MAAS API vulnerable to CSRF attack
Published 2019-04-22 · Modified
9.6EPSS 0.011
CVE-2014-1426
get_file_by_name does not check owner
Published 2019-04-22 · Modified
8.6EPSS 0.014
CVE-2014-1428
uuid.uuid1() is not suitable as an unguessable identifier/token
Published 2019-04-22 · Modified
5.3EPSS 0.009