CVE-2015-1320: Canonical Metal As A Service

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu MAAS versions prior to 1.9.2.

Affected products

  • Canonical Metal As A Service: before 1.9.2 (fixed in 1.9.2)

Published 2019-04-22. Last modified 2026-06-17.