The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information.
2025-07-08T17:16:04.400
2025-08-26T17:54:14.010
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | canonical | juju | < 2.9.52 | Yes |
Application | canonical | juju | < 3.6.8 | Yes |