Описание
The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| jammy | DNE | |
| noble | DNE | |
| plucky | DNE | |
| snap | released | 3.6.8 |
| upstream | released | 2.9.52, 3.6.8 |
Показывать по
Ссылки на источники
EPSS
8.8 High
CVSS3
Связанные уязвимости
The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.
The /charms endpoint on a Juju controller lacked sufficient authorizat ...
Juju zip slip vulnerability via authenticated endpoint
EPSS
8.8 High
CVSS3