Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6rm3-6fxh-j77h

Опубликовано: 03 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment.

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment.

EPSS

Процентиль: 11%
0.00036
Низкий

7.7 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.7
nvd
2 месяца назад

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment.

EPSS

Процентиль: 11%
0.00036
Низкий

7.7 High

CVSS3

Дефекты

CWE-269