Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-4370

Опубликовано: 02 апр. 2026
Источник: ubuntu
Приоритет: critical
EPSS Низкий
CVSS3: 10

Описание

A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's database endpoint does not validate client certificates when a new node attempts to join the cluster. An unauthenticated attacker with network reachability to the Juju controller's Dqlite port can exploit this flaw to join the database cluster. Once joined, the attacker gains full read and write access to the underlying database, allowing for total data compromise.

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

DNE

questing

DNE

snap

released

3.6.20, 4.0.5
upstream

needs-triage

Показывать по

EPSS

Процентиль: 22%
0.00071
Низкий

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
nvd
9 дней назад

A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's database endpoint does not validate client certificates when a new node attempts to join the cluster. An unauthenticated attacker with network reachability to the Juju controller's Dqlite port can exploit this flaw to join the database cluster. Once joined, the attacker gains full read and write access to the underlying database, allowing for total data compromise.

CVSS3: 10
debian
9 дней назад

A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 ...

CVSS3: 10
github
8 дней назад

Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster

EPSS

Процентиль: 22%
0.00071
Низкий

10 Critical

CVSS3