CVE-2013-1069: Low severity Ubuntu Metal as a Service vulnerability
Published Feb 17, 2014
·Updated
Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.
Affected Software
2 affected components
Ubuntu Metal as a Service=1.2
Ubuntu Metal as a Service=1.4
Event History
Feb 17, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1069?
CVE-2013-1069 has a medium severity rating due to the exposure of sensitive RabbitMQ authentication credentials.
2
How do I fix CVE-2013-1069?
To fix CVE-2013-1069, change the permissions of the txlongpoll.yaml file to restrict access to authorized users only.
3
What versions of Ubuntu Metal as a Service are affected by CVE-2013-1069?
CVE-2013-1069 affects Ubuntu Metal as a Service versions 1.2 and 1.4.
4
What type of exposure does CVE-2013-1069 create?
CVE-2013-1069 allows local users to read RabbitMQ authentication credentials due to world-readable file permissions.
5
Is CVE-2013-1069 a local or remote vulnerability?
CVE-2013-1069 is a local vulnerability, as it requires local access to the system to exploit.