Canonical

Maas

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 02.10.2026 19:24:09
  • Zuletzt bearbeitet 06.10.2026 16:00:36

An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine wa...

  • EPSS 0.27%
  • Veröffentlicht 03.12.2025 15:45:47
  • Zuletzt bearbeitet 18.12.2025 21:01:26

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly val...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 21.07.2025 08:52:56
  • Zuletzt bearbeitet 27.08.2025 14:30:39

Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.

  • EPSS 1.94%
  • Veröffentlicht 23.11.2013 18:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.

Exploit
  • EPSS 0.59%
  • Veröffentlicht 18.11.2013 02:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current working directory.