CVE-2014-1428: uuid.uuid1() is not suitable as an unguessable identifier/token
Published Apr 22, 2019
·Updated
A vulnerability in generatefilestoragekey of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2.
Affected Software
1 affected component
Canonical Metal As A Service<1.9.2
Event History
Apr 22, 2019
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2014-1428?
CVE-2014-1428 is classified as a moderate severity vulnerability due to its potential for exploitation via brute-force attacks.
2
How do I fix CVE-2014-1428?
To fix CVE-2014-1428, upgrade Ubuntu MAAS to version 1.9.2 or later.
3
What software is affected by CVE-2014-1428?
CVE-2014-1428 affects Ubuntu MAAS versions prior to 1.9.2.
4
Can CVE-2014-1428 lead to unauthorized access?
Yes, CVE-2014-1428 can allow attackers to brute-force filenames, potentially leading to unauthorized access.
5
Is there a workaround for CVE-2014-1428?
There are no official workarounds for CVE-2014-1428, so upgrading to a patched version is recommended.