Vulnerabilities
Vulnerable Software
Canonical:  >> Maas  Security Vulnerabilities
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment.
CVSS Score
7.7
EPSS Score
0.0
Published
2025-12-03
maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
CVSS Score
5.8
EPSS Score
0.007
Published
2013-11-23
Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current working directory.
CVSS Score
4.4
EPSS Score
0.001
Published
2013-11-18


Contact Us

Shodan ® - All rights reserved