Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-68153

Опубликовано: 03 апр. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, any authenticated user, machine or controller under a Juju controller can modify the resources of an application within the entire controller. This issue has been patched in versions 2.9.56 and 3.6.19.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
Версия от 2.9 (включая) до 2.9.55 (включая)
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
Версия от 3.6 (включая) до 3.6.18 (включая)

EPSS

Процентиль: 14%
0.00232
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, any authenticated user, machine or controller under a Juju controller can modify the resources of an application within the entire controller. This issue has been patched in versions 2.9.56 and 3.6.19.

CVSS3: 6.5
debian
4 месяца назад

Juju is an open source application orchestration engine that enables a ...

CVSS3: 6.5
github
4 месяца назад

Juju has a resource poisoning vulnerability

EPSS

Процентиль: 14%
0.00232
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863