Canonical Metal As A Service vulnerabilities
5 known vulnerabilities affecting canonical/metal_as_a_service.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-6107CRITICALCVSS 9.8≥ 3.1.0, < 3.1.4≥ 3.2.0, < 3.2.11+3 more2025-07-21
CVE-2024-6107 [CRITICAL] CWE-287 CVE-2024-6107: Due to insufficient verification, an attacker could use a malicious client to bypass authentication
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
nvd
CVE-2015-1320CRITICALCVSS 9.8fixed in 1.9.22019-04-22
CVE-2015-1320 [MEDIUM] CWE-255 CVE-2015-1320: The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the
The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu MAAS versions prior to 1.9.2.
nvd
CVE-2014-1426HIGHCVSS 7.5fixed in 1.9.22019-04-22
CVE-2014-1426 [HIGH] CWE-20 CVE-2014-1426: A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network cli
A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ubuntu MAAS versions prior to 1.9.2.
nvd
CVE-2014-1428MEDIUMCVSS 5.3fixed in 1.9.22019-04-22
CVE-2014-1428 [LOW] CWE-254 CVE-2014-1428: A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenam
A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2.
nvd
CVE-2014-1427MEDIUMCVSS 6.1fixed in 1.9.22019-04-22
CVE-2014-1427 [CRITICAL] CWE-79 CVE-2014-1427: A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execu
A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue affects MAAS versions prior to 1.9.2.
nvd