7.7
CVE-2025-7044
- EPSS 0.03%
- Veröffentlicht 03.12.2025 15:45:47
- Zuletzt bearbeitet 04.12.2025 17:15:08
- Quelle security@ubuntu.com
- CVE-Watchlists
- Unerledigt
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerUbuntu
≫
Produkt
MAAS
Default Statusunaffected
Version <
3.3.11
Version
3.3.0
Status
affected
Version <
3.4.9
Version
3.4.0
Status
affected
Version <
3.5.9
Version
3.5.0
Status
affected
Version <
3.6.2
Version
3.6.0
Status
affected
Version
3.7.0
Status
unaffected
Version
3.8.0
Status
unaffected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.085 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@ubuntu.com | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.