Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ubuntu Metal as a Service 安全漏洞
Vulnerability Description
Ubuntu Metal as a Service(MaaS)是英国科能(Canonical)公司和Ubuntu基金会共同开发的一套云服务器部署和管理工具。该工具可对大量服务器的硬件环境进行集中部署并管理。 Ubuntu MaaS 1.2和1.4版本中存在安全漏洞,该漏洞源于程序对txlongpoll.yaml文件使用全局可读权限。本地攻击者可通过读取文件利用该漏洞获取RabbitMQ身份验证凭证。
CVSS Information
N/A
Vulnerability Type
N/A