Vulnerabilities > Ubuntu > Metal AS A Service > 1.4

DATE CVE VULNERABILITY TITLE RISK
2014-02-17 CVE-2013-1070 Cross-Site Scripting vulnerability in Ubuntu Metal AS A Service 1.2/1.4
Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/.
network
ubuntu CWE-79
4.3
2014-02-17 CVE-2013-1069 Permissions, Privileges, and Access Controls vulnerability in Ubuntu Metal AS A Service 1.2/1.4
Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.
local
low complexity
ubuntu CWE-264
2.1