PT-2019-7076 · Canonical · Ubuntu Maas

Blake Rouse

·

Published

2019-04-22

·

Updated

2019-10-09

·

CVE-2014-1426

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ubuntu MAAS versions prior to 1.9.2
Description A vulnerability in the maasserver.api.get file by name function of Ubuntu MAAS allows unauthenticated network clients to download any file.
Recommendations For versions prior to 1.9.2, update to version 1.9.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the maasserver.api.get file by name function to prevent unauthorized file downloads.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1426

Affected Products

Ubuntu Maas