Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-1237

Опубликовано: 28 янв. 2026
Источник: ubuntu
Приоритет: low
EPSS Низкий

Описание

Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing.

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

DNE

questing

DNE

snap

deferred

upstream

needs-triage

Показывать по

EPSS

Процентиль: 0%
0.00005
Низкий

Связанные уязвимости

nvd
2 месяца назад

Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing.

debian
2 месяца назад

Vulnerable cross-model authorization in juju. If a charm's cross-model ...

github
2 месяца назад

Juju has broken CMR authorization

EPSS

Процентиль: 0%
0.00005
Низкий