Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current working directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ubuntu MAAS Server 本地提权漏洞
Vulnerability Description
Ubuntu MAAS Server(Metal as a Service)是英国科能(Canonical)公司和Ubuntu基金会共同开发的一套云服务器部署和管理工具。该工具可对大量服务器的硬件环境进行集中部署并管理。 MAAS 13.10之前的版本中的‘maas-import-pxe-files’设置文件中存在未限制搜索路径漏洞,该漏洞源于‘maas-import-pxe-files’设置文件错误的加载当前工作目录的配置信息。本地攻击者可利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A