Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.36% | — | Canonical Metal AS A Service | 21/7/2025 | 17/6/2026 | Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps. | |
| Modificada | Crítica (9.8) | 0.87% | — | Canonical Metal AS A Service | 22/4/2019 | 17/6/2026 | The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu MAAS versions prior to 1.9.2. | |
| Modificada | Media (5.3) | 0.95% | — | Canonical Metal AS A Service | 22/4/2019 | 17/6/2026 | A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2. | |
| Modificada | Media (6.1) | 1.1% | — | Canonical Metal AS A Service | 22/4/2019 | 17/6/2026 | A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue affects MAAS versions prior to 1.9.2. | |
| Modificada | Alta (7.5) | 1.4% | — | Canonical Metal AS A Service | 22/4/2019 | 17/6/2026 | A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ubuntu MAAS versions prior to 1.9.2. | |
| Modificada | Media (4.3) | 2.4% | — | Ubuntu Metal AS A Service | 17/2/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/. | |
| Modificada | Baja (2.1) | 0.38% | — | Ubuntu Metal AS A Service | 17/2/2014 | 16/6/2026 | Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file. |