Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfgr-6hrj-85ww

Опубликовано: 19 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Juju affected by timing ownership claim attack on new external back-end secrets

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision.

Impact

Between generating a Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision.

Patches

3.6.19

Пакеты

Наименование

github.com/juju/juju

go
Затронутые версииВерсия исправления

>= 3.0.0, < 3.6.19

3.6.19

EPSS

Процентиль: 2%
0.00012
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-708

Связанные уязвимости

CVSS3: 5.3
ubuntu
11 дней назад

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision.

CVSS3: 5.3
nvd
11 дней назад

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision.

CVSS3: 5.3
debian
11 дней назад

A race condition in the secrets management subsystem of Juju versions ...

EPSS

Процентиль: 2%
0.00012
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-708