Back

MEDIUM

The ops library leaks secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command

Published Jul 22, 2024

Description

The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that ops passes the secret content as one of the args via CLI. This issue may affect any of the charms that are using: Juju (>=3.0), Juju secrets and not correctly capturing and processing `subprocess.CalledProcessError`. This vulnerability is fixed in 2.15.0.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 22, 2024
Updated Aug 2, 2024
Reserved Jul 15, 2024
CISA Vulnrichment
Updated Jul 22, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-HCMV-JMQH-FJGM