Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-5412

4 месяца назад

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.

CVSS3: 9.9
EPSS: Низкий
nvd логотип

CVE-2026-5412

4 месяца назад

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.

CVSS3: 9.9
EPSS: Низкий
debian логотип

CVE-2026-5412

4 месяца назад

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue ex ...

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-w5fq-8965-c969

4 месяца назад

Juju: CloudSpec method leaking cloud credentials

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-5412

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.

CVSS3: 9.9
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-5412

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.

CVSS3: 9.9
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-5412

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue ex ...

CVSS3: 9.9
0%
Низкий
4 месяца назад
github логотип
GHSA-w5fq-8965-c969

Juju: CloudSpec method leaking cloud credentials

CVSS3: 9.9
0%
Низкий
4 месяца назад

Уязвимостей на страницу