Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ubuntu MAAS Server 中间人攻击漏洞
Vulnerability Description
Ubuntu MAAS Server(Metal as a Service)是英国科能(Canonical)公司和Ubuntu基金会共同开发的一套云服务器部署和管理工具。该工具可对大量服务器的硬件环境进行集中部署并管理。 MAAS 13.10之前的版本中的maas-import-pxe-files配置文件中存在安全漏洞,该漏洞源于程序没有验证下载文件的完整性。远程攻击者可通过中间人攻击利用该漏洞修改下载的文件。
CVSS Information
N/A
Vulnerability Type
N/A