VendorsUbuntumetal_as_a_serviceall versions
Vulnerabilities

Ubuntu Metal As A Service

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2013-1070
Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/.
Published 2014-02-17 · Modified
4.3EPSS 0.024
CVE-2013-1069
Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.
Published 2014-02-17 · Modified
2.1EPSS 0.004