Metal as a service
This hub aggregates every CVE we track for Metal as a service, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
2
Critical
1
High
0
In CISA KEV
Severity distribution
LOW2MEDIUM2CRITICAL2HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 7 most recently published vulnerabilities affecting Metal as a service.
- CVE-2024-6107Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corre...9.6
- CVE-2015-1320Probe-and-enlist for SeaMicro chassis writes password to the log5.5
- CVE-2014-1428uuid.uuid1() is not suitable as an unguessable identifier/token2.0
- CVE-2014-1427MAAS API vulnerable to CSRF attack9.6
- CVE-2014-1426get_file_by_name does not check owner8.6
- CVE-2013-1069Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.2.1
- CVE-2013-1070Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/.4.3
Product normalization is registry-driven with AI assist and human review. How it works