Описание
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment.
Ссылки
- Third Party Advisory
Уязвимые конфигурации
Одно из
EPSS
7.7 High
CVSS3
6.5 Medium
CVSS3
Дефекты
Связанные уязвимости
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment.
EPSS
7.7 High
CVSS3
6.5 Medium
CVSS3