Количество 4
Количество 4
CVE-2026-32693
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee.
CVE-2026-32693
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee.
CVE-2026-32693
In Juju from version 3.0.0 through 3.6.18, the authorization of the "s ...
GHSA-439w-v2p7-pggc
Juju has unauthorized access to out-of-scope Kubernetes secrets
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-32693 In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee. | CVSS3: 8.8 | 0% Низкий | 11 дней назад | |
CVE-2026-32693 In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee. | CVSS3: 8.8 | 0% Низкий | 11 дней назад | |
CVE-2026-32693 In Juju from version 3.0.0 through 3.6.18, the authorization of the "s ... | CVSS3: 8.8 | 0% Низкий | 11 дней назад | |
GHSA-439w-v2p7-pggc Juju has unauthorized access to out-of-scope Kubernetes secrets | CVSS3: 8.8 | 0% Низкий | 10 дней назад |
Уязвимостей на страницу