Canonical Ubuntu Metal as a Service(MAAS)是英国科能(Canonical)公司的一套云服务器部署和管理工具。该工具可对大量服务器的硬件环境进行集中部署并管理。 Ubuntu MAAS 1.9.2之前版本中的‘maasserver.api.get_file_by_name’函数存在安全漏洞。攻击者可利用该漏洞下载任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-1427 | MAAS API vulnerable to CSRF attack | |
| CVE-2014-1428 | uuid.uuid1() is not suitable as an unguessable identifier/token | |
| CVE-2015-1316 | Juju Joyent provider uploads user's private ssh key by default | |
| CVE-2015-1320 | Probe-and-enlist for SeaMicro chassis writes password to the log | |
| CVE-2015-1326 | python-dbusmock arbitrary code execution or file overwrite when templates are loaded from | |
| CVE-2015-1327 | Content-hub DBUS API doesn't prevent confined apps from passing paths to files without acc | |
| CVE-2015-1340 | chmod race in doUidshiftIntoContainer | |
| CVE-2015-1341 | Apport privilege escalation through Python module imports | |
| CVE-2015-1343 | unity-scope-gdrive search feature logs search terms to syslog | |
| CVE-2016-1573 | Using a specially crafted fallback art property, scopes can execute arbitrary QML code in | |
| CVE-2016-1579 | UDM doesn't check for confinement before running post-processing commands | |
| CVE-2016-1584 | Unity8 converged application lifecycle allows background applications to use on-screen key | |
| CVE-2016-1586 | Oxide 输入验证错误漏洞 | |
| CVE-2016-1587 | Snapweb interface 访问控制错误漏洞 |
No comments yet