Home
CRITICAL: 9.6 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:HDefault status
affected
3.1.0 (semver) before 3.1.4
affected
3.2.0 (semver) before 3.2.11
affected
3.3.0 (semver) before 3.3.8
affected
3.4.0 (semver) before 3.4.4
affected
3.5.0 (semver) before 3.5.1
affected
Description
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
Problem types
Product status
3.1.0 (semver) before 3.1.4
3.2.0 (semver) before 3.2.11
3.3.0 (semver) before 3.3.8
3.4.0 (semver) before 3.4.4
3.5.0 (semver) before 3.5.1
References
bugs.launchpad.net/maas/+bug/2069094