Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89x7-5m5m-mcmm

Опубликовано: 19 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.6

Описание

Juju has unauthorized update of out-of-scope Vault secrets

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

Impact

An authenticated unit agent can update any secret revision of a Vault back-end that the unit's model uses. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

Patches

3.6.19

Пакеты

Наименование

github.com/juju/juju

go
Затронутые версииВерсия исправления

>= 0.0.0-20230919230135-f6a66aa91eec, < 0.0.0-20260319091847-d06919eb03ec

0.0.0-20260319091847-d06919eb03ec

EPSS

Процентиль: 9%
0.0003
Низкий

7.6 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 7.6
ubuntu
11 дней назад

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

CVSS3: 7.6
nvd
11 дней назад

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

CVSS3: 7.6
debian
11 дней назад

An authorization bypass vulnerability in the Vault secrets back-end im ...

EPSS

Процентиль: 9%
0.0003
Низкий

7.6 High

CVSS3

Дефекты

CWE-285