get_file_by_name does not check owner
CVE-2014-1426
8.6HIGH
What is CVE-2014-1426?
A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ubuntu MAAS versions prior to 1.9.2.
Affected Version(s)
maas < 1.9.2