CVE-2014-1426: get_file_by_name does not check owner
Published Apr 22, 2019
·Updated
A vulnerability in maasserver.api.getfilebyname of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ubuntu MAAS versions prior to 1.9.2.
Affected Software
1 affected component
Canonical Metal As A Service<1.9.2
Event History
Apr 22, 2019
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2014-1426?
CVE-2014-1426 is considered a high severity vulnerability due to its potential for unauthorized access to sensitive files.
2
How do I fix CVE-2014-1426?
To fix CVE-2014-1426, upgrade to Ubuntu MAAS version 1.9.2 or later.
3
Who is affected by CVE-2014-1426?
CVE-2014-1426 affects users of Ubuntu MAAS versions prior to 1.9.2.
4
What is the impact of CVE-2014-1426?
The impact of CVE-2014-1426 allows unauthenticated network clients to download arbitrary files from the server.
5
What components are involved in CVE-2014-1426?
CVE-2014-1426 specifically involves the maasserver.api.get_file_by_name function within the Ubuntu MAAS application.