Canonical MAAS
cpe:2.3:a:canonical:metal_as_a_service:*:*:*:*:*:*:*
A vulnerability allowing improper input validation has been identified in the user websocket handler of MAAS. This issue enables an authenticated, unprivileged attacker to intercept websocket requests related to user updates and inject the is_superuser property, setting it to true. The server's failure to properly validate this input allows the attacker to elevate their privileges to an administrator role, granting full administrative control over the MAAS deployment.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling an attacker to gain full administrative rights within the MAAS environment.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.