Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-68152

Опубликовано: 03 апр. 2026
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, it is possible that a compromised workload machine under a Juju controller can read any log file for any entity in any model at any level. This issue has been patched in versions 2.9.56 and 3.6.19.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
Версия от 2.9 (включая) до 2.9.55 (включая)
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
Версия от 3.6 (включая) до 3.6.18 (включая)

EPSS

Процентиль: 29%
0.00362
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.9
ubuntu
5 месяцев назад

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, it is possible that a compromised workload machine under a Juju controller can read any log file for any entity in any model at any level. This issue has been patched in versions 2.9.56 and 3.6.19.

CVSS3: 4.9
debian
5 месяцев назад

Juju is an open source application orchestration engine that enables a ...

CVSS3: 4.9
github
5 месяцев назад

Juju: Read All Controller Logs From Compromised Workload

EPSS

Процентиль: 29%
0.00362
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-863