Search

Find a vulnerability

Search criteria

    2 vulnerabilities found for MAAS by Canonical

    CVE-2026-12392 (GCVE-0-2026-12392)

    Vulnerability from cvelistv5 – Published: 2026-10-02 19:24 – Updated: 2026-10-03 15:52
    VLAI
    Title
    RPC secret disclosure via vendor data endpoint in Canonical MAAS
    Summary
    An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker who obtains or infers the machine's system ID can query the preseed/metadata server to leak the secret.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:47 UTC
    Impacted products
    Vendor Product Version
    Canonical MAAS Affected: 3.4.0 , < 3.4.10 (semver)
    Affected: 3.5.0 , < 3.5.14 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.7.0 , < 3.7.3 (semver)
    Affected: 0 , < 3.8.0 (semver)
        cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*
        cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*
        cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*
        cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*
        cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-12392",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:47:50.712440Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:52:55.367Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "maas",
              "platforms": [
                "Linux"
              ],
              "product": "MAAS",
              "repo": "https://github.com/canonical/maas",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "3.4.10",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.14",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.7.3",
                  "status": "affected",
                  "version": "3.7.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.8.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*",
                      "versionEndExcluding": "3.4.10",
                      "versionStartIncluding": "3.4.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*",
                      "versionEndExcluding": "3.5.14",
                      "versionStartIncluding": "3.5.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*",
                      "versionEndExcluding": "3.6.5",
                      "versionStartIncluding": "3.6.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*",
                      "versionEndExcluding": "3.7.3",
                      "versionStartIncluding": "3.7.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:canonical:maas:*:*:linux:*:*:*:*:*",
                      "versionEndExcluding": "3.8.0",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the \u0027register as rack\u0027 option enabled, an attacker who obtains or infers the machine\u0027s system ID can query the preseed/metadata server to leak the secret."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T19:24:09.110Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/maas/commit/8489979d64b0e7f124e7cef66d02b21263918f9b"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/maas/commit/a9486ad0cc90f4571142c1bea13f02d1361cb31e"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/maas/commit/ead659f70224538517c80478c3fd8c9e730aae79"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/maas/commit/3864ef9dca54e36e3d34d18233b87666b8ee1dc8"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/maas/commit/65e89c05970f4514f9e6de043c2779017b43ad9d"
            },
            {
              "tags": [
                "vendor-advisory",
                "issue-tracking"
              ],
              "url": "https://bugs.launchpad.net/maas/+bug/2153942"
            }
          ],
          "title": "RPC secret disclosure via vendor data endpoint in Canonical MAAS",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-12392",
        "datePublished": "2026-10-02T19:24:09.110Z",
        "dateReserved": "2026-06-16T12:16:09.502Z",
        "dateUpdated": "2026-10-03T15:52:55.367Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-6107 (GCVE-0-2024-6107)

    Vulnerability from cvelistv5 – Published: 2025-07-21 08:52 – Updated: 2025-07-21 17:07
    VLAI
    Summary
    Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-21 17:06 UTC
    CWE
    • CWE-287 - When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
    References
    Impacted products
    Vendor Product Version
    Canonical MAAS Affected: 3.1.0 , < 3.1.4 (semver)
    Affected: 3.2.0 , < 3.2.11 (semver)
    Affected: 3.3.0 , < 3.3.8 (semver)
    Affected: 3.4.0 , < 3.4.4 (semver)
    Affected: 3.5.0 , < 3.5.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6107",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-21T17:06:46.994969Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-07-21T17:07:16.633Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "packageName": "maas",
              "platforms": [
                "Linux"
              ],
              "product": "MAAS",
              "repo": "https://git.launchpad.net/maas/",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "3.1.4",
                  "status": "affected",
                  "version": "3.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.2.11",
                  "status": "affected",
                  "version": "3.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.3.8",
                  "status": "affected",
                  "version": "3.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.4",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.1",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "This vulnerability allows attackers with a malicious client to execute RPC commands on the region without authentication."
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.6,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-07-21T08:52:56.608Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "url": "https://bugs.launchpad.net/maas/+bug/2069094"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2024-6107",
        "datePublished": "2025-07-21T08:52:56.608Z",
        "dateReserved": "2024-06-18T00:31:47.270Z",
        "dateUpdated": "2025-07-21T17:07:16.633Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }