在 Canonical MAAS 版本 3.4.10、3.5.14、3.6.5、3.7.3 及 3.8.0 之前的版本中存在信息泄露漏洞,未认证的攻击者可通过供应商数据元数据端点以明文方式获取 RPC 密钥。如果目标机器在部署时启用了“注册为机架”(register as rack)选项,则任何获得或推断出该系统 ID 的攻击者均可查询 preseed/元数据服务器,从而泄露该密钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet