Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-53513

Опубликовано: 08 июл. 2025
Источник: nvd
CVSS3: 8.8
CVSS3: 6.5
EPSS Низкий

Описание

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
Версия до 2.9.52 (исключая)
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
Версия от 3.0 (включая) до 3.6.8 (исключая)

EPSS

Процентиль: 27%
0.00096
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-24
CWE-22

Связанные уязвимости

CVSS3: 8.8
ubuntu
7 месяцев назад

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.

CVSS3: 8.8
debian
7 месяцев назад

The /charms endpoint on a Juju controller lacked sufficient authorizat ...

CVSS3: 8.8
github
7 месяцев назад

Juju zip slip vulnerability via authenticated endpoint

EPSS

Процентиль: 27%
0.00096
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-24
CWE-22