Описание
The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| jammy | DNE | |
| noble | DNE | |
| plucky | DNE | |
| snap | released | 3.6.8 |
| upstream | released | 2.9.52, 3.6.8 |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 17%
0.00053
Низкий
6.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.5
nvd
7 месяцев назад
The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information.
CVSS3: 6.5
debian
7 месяцев назад
The /log endpoint on a Juju controller lacked sufficient authorization ...
CVSS3: 6.5
github
7 месяцев назад
Juju vulnerable to sensitive log retrieval via authenticated endpoint without authorization
EPSS
Процентиль: 17%
0.00053
Низкий
6.5 Medium
CVSS3