An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.
2024-07-29T14:15:04.477
2024-11-21T09:50:41.767
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | canonical | juju | < 2.9.50 | Yes |
Application | canonical | juju | < 3.1.9 | Yes |
Application | canonical | juju | < 3.3.6 | Yes |
Application | canonical | juju | < 3.4.5 | Yes |
Application | canonical | juju | < 3.5.3 | Yes |