Juju controller - Arbitrary file reading vulnerability
Package
Affected versions
>= 2.9.22, < 2.9.38
>= 3.0.0, < 3.0.3
Patched versions
2.9.38
3.0.3
Description
Published to the GitHub Advisory Database
Mar 1, 2023
Reviewed
Mar 1, 2023
Published by the National Vulnerability Database
Jan 31, 2025
Last updated
Jan 31, 2025
Impact
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
Patches
Patched in juju 2.9.38 and juju 3.0.3
juju/juju#ef803e2
Workarounds
Limit read access to the controller model to only trusted users.
References