An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LCanonical Juju
APPCanonical3.1.6 – 3.6.19 (bez)
Powiązane podatności
Canonical Juju — nieuprawniony dostęp do poświadczeń chmury przez Controller facade
Canonical Juju: brak uwierzytelnienia TLS w klastrze Dqlite umożliwia przejęcie bazy danych
Privilege escalation w Juju przez niezabezpieczony UNIX domain socket
Juju is an open source application orchestration engine that enables any application operation on any infrastr...
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correct...