Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-32692

Опубликовано: 18 мар. 2026
Источник: debian
EPSS Низкий

Описание

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jujuremovedpackage

EPSS

Процентиль: 7%
0.00027
Низкий

Связанные уязвимости

CVSS3: 7.6
ubuntu
11 дней назад

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

CVSS3: 7.6
nvd
11 дней назад

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

CVSS3: 7.6
github
10 дней назад

Juju has unauthorized update of out-of-scope Vault secrets

EPSS

Процентиль: 7%
0.00027
Низкий