Описание
Juju controller - Arbitrary file reading vulnerability
Impact
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
Patches
Patched in juju 2.9.38 and juju 3.0.3 juju/juju#ef803e2
Workarounds
Limit read access to the controller model to only trusted users.
Пакеты
github.com/juju/juju
>= 2.9.22, < 2.9.38
2.9.38
github.com/juju/juju
>= 3.0.0, < 3.0.3
3.0.3
Связанные уязвимости
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
An authenticated user who has read access to the juju controller model ...