PT-2019-7076 · Canonical · Ubuntu Maas

Blake Rouse

·

Publicado

2019-04-22

·

Atualizado

2019-10-09

·

CVE-2014-1426

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ubuntu MAAS versions prior to 1.9.2
Description A vulnerability in the maasserver.api.get file by name function of Ubuntu MAAS allows unauthenticated network clients to download any file.
Recommendations For versions prior to 1.9.2, update to version 1.9.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the maasserver.api.get file by name function to prevent unauthorized file downloads.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-1426

Produtos afetados

Ubuntu Maas