CVE-2013-1070: XSS
Published Feb 17, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/.
Affected Software
2 affected components
Ubuntu Metal as a Service=1.2
Ubuntu Metal as a Service=1.4
Event History
Feb 17, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1070?
CVE-2013-1070 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2013-1070?
To fix CVE-2013-1070, upgrade Ubuntu Metal as a Service to version 1.5 or later.
3
What software versions are affected by CVE-2013-1070?
CVE-2013-1070 affects Ubuntu Metal as a Service versions 1.2 and 1.4.
4
Who can exploit CVE-2013-1070?
Remote attackers can exploit CVE-2013-1070 by injecting arbitrary web scripts through the op parameter.
5
What type of vulnerability is CVE-2013-1070?
CVE-2013-1070 is a cross-site scripting (XSS) vulnerability.