First published: Mon Feb 17 2014(Updated: )
Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Canonical Metal As A Service | =1.2 | |
Canonical Metal As A Service | =1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1069 has a medium severity rating due to the exposure of sensitive RabbitMQ authentication credentials.
To fix CVE-2013-1069, change the permissions of the txlongpoll.yaml file to restrict access to authorized users only.
CVE-2013-1069 affects Ubuntu Metal as a Service versions 1.2 and 1.4.
CVE-2013-1069 allows local users to read RabbitMQ authentication credentials due to world-readable file permissions.
CVE-2013-1069 is a local vulnerability, as it requires local access to the system to exploit.