Canonical / Juju
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-5412 | Juju CloudSpec API could leak senstive information | CRITICAL | 9.9 | Apr 10, 2026 |
| CVE-2026-5774 | Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map | MEDIUM | 6.1 | Apr 10, 2026 |
| CVE-2025-68153 | Juju: Resource poisoning | HIGH | 7.1 | Apr 3, 2026 |
| CVE-2025-68152 | Juju: Read All Controller Logs From Compromised Workload | MEDIUM | 6.9 | Apr 3, 2026 |
| CVE-2026-4370 | Improper TLS Client/Server authentication and certificate verification on Database Cluster | CRITICAL | 10.0 | Apr 1, 2026 |
| CVE-2026-32694 | Insecure Direct Object Reference attack via predictable secret ID in Juju | MEDIUM | 6.6 | Mar 18, 2026 |
| CVE-2026-32693 | Unauthorized access to Kubernetes secrets in Juju | HIGH | 8.8 | Mar 18, 2026 |
| CVE-2026-32692 | Unauthorized update of out-of-scope Vault secrets | HIGH | 7.6 | Mar 18, 2026 |
| CVE-2026-32691 | Timing ownership claim attack on new external back-end secrets | MEDIUM | 5.3 | Mar 18, 2026 |
| CVE-2026-1237 | Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database recor… | LOW | 2.1 | Jan 28, 2026 |
| CVE-2025-0928 | Arbitrary executable upload via authenticated endpoint | HIGH | 8.8 | Jul 8, 2025 |
| CVE-2025-53513 | Zip slip vulnerability in Juju | HIGH | 8.8 | Jul 8, 2025 |
| CVE-2025-53512 | Sensitive log retrieval in Juju | MEDIUM | 6.5 | Jul 8, 2025 |
| CVE-2023-0092 | An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's file… | MEDIUM | 4.9 | Jan 31, 2025 |
| CVE-2024-8038 | Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication loc… | MEDIUM | 6.2 | Oct 2, 2024 |
| CVE-2024-8037 | Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default… | MEDIUM | 6.2 | Oct 2, 2024 |
| CVE-2024-7558 | JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the… | MEDIUM | 6.2 | Oct 2, 2024 |
| CVE-2024-6984 | An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive dat… | HIGH | 8.8 | Jul 29, 2024 |
| CVE-2015-1316 | Juju Joyent provider uploads user's private ssh key by default | HIGH | 7.5 | Apr 22, 2019 |
| CVE-2017-9232 | Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalatio… | CRITICAL | 9.8 | May 28, 2017 |
Showing 1 to 20 of 20 CVEs