CVE-2013-1069
Ubuntu Security Notice USN-2105-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.
Ubuntu Metal como un servicio (MaaS) 1.2 y 1.4 utiliza permisos de lectura para todos para txlongpoll.yaml, lo que permite a usuarios locales obtener credenciales de autenticación de RabbitMQ mediante la lectura del archivo.
James Troup discovered that MAAS stored RabbitMQ authentication credentials in a world-readable file. A local authenticated user could read this password and potentially gain privileges of other user accounts. This update restricts the file permissions to prevent unintended access. Chris Glass discovered that the MAAS API was vulnerable to cross-site scripting vulnerabilities. With cross-site scripting vulnerabilities, if a user were tricked into viewing a specially crafted page, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-01-11 CVE Reserved
- 2014-02-14 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://bugs.launchpad.net/ubuntu/%2Bsource/maas/%2Bbug/1254034 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ubuntu.com/usn/USN-2105-1 | 2014-02-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ubuntu Search vendor "Ubuntu" | Metal As A Service Search vendor "Ubuntu" for product "Metal As A Service" | 1.2 Search vendor "Ubuntu" for product "Metal As A Service" and version "1.2" | - |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Metal As A Service Search vendor "Ubuntu" for product "Metal As A Service" | 1.4 Search vendor "Ubuntu" for product "Metal As A Service" and version "1.4" | - |
Affected
|