uuid.uuid1() is not suitable as an unguessable identifier/token
CVE-2014-1428

2LOW

Key Information:

Vendor

Ubuntu

Status
Vendor
CVE Published:
22 April 2019

What is CVE-2014-1428?

A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2.

Affected Version(s)

MAAS < 1.9.2

References

CVSS V3.1

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.