Vulnerabilities > Ubuntu > Metal AS A Service > 1.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-02-17 | CVE-2013-1070 | Cross-Site Scripting vulnerability in Ubuntu Metal AS A Service 1.2/1.4 Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/. | 4.3 |
2014-02-17 | CVE-2013-1069 | Permissions, Privileges, and Access Controls vulnerability in Ubuntu Metal AS A Service 1.2/1.4 Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file. | 2.1 |