CVE-2013-1070

Publication date 13 February 2014

Last updated 24 July 2024


Ubuntu priority

Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/.

Status

Package Ubuntu Release Status
maas 13.10 saucy
Fixed 1.4+bzr1693+dfsg-0ubuntu2.3
12.10 quantal
Fixed 1.2+bzr1373+dfsg-0ubuntu1.2
12.04 LTS precise
Fixed 1.2+bzr1373+dfsg-0ubuntu1~12.04.5
10.04 LTS lucid Not in release

References

Related Ubuntu Security Notices (USN)

    • USN-2105-1
    • MAAS vulnerabilities
    • 13 February 2014

Other references