Vulnerabilities
Vulnerable Software
A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ubuntu MAAS versions prior to 1.9.2.
CVSS Score
8.6
EPSS Score
0.007
Published
2019-04-22
A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue affects MAAS versions prior to 1.9.2.
CVSS Score
9.6
EPSS Score
0.004
Published
2019-04-22
A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2.
CVSS Score
2.0
EPSS Score
0.002
Published
2019-04-22
The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu MAAS versions prior to 1.9.2.
CVSS Score
5.5
EPSS Score
0.002
Published
2019-04-22


Contact Us

Shodan ® - All rights reserved