A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue affects MAAS versions prior to 1.9.2.
{
"binaries": [
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "maas"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "maas-cli"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "maas-cluster-controller"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "maas-common"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "maas-dhcp"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "maas-dns"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "maas-proxy"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "maas-region-controller"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "maas-region-controller-min"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "python-django-maas"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "python-maas-client"
},
{
"binary_version": "1.9.5+bzr4599-0ubuntu1~14.04.1",
"binary_name": "python-maas-provisioningserver"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas-cli"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas-common"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas-dhcp"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas-dns"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas-proxy"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas-rack-controller"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas-rack-udeb"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas-region-api"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas-region-controller"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "maas-region-udeb"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "python3-django-maas"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "python3-maas-client"
},
{
"binary_version": "2.1.3+bzr5573-0ubuntu1~16.04.1",
"binary_name": "python3-maas-provisioningserver"
}
],
"availability": "No subscription required"
}