📦 Juju

by Canonical

🔍 What is Juju?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-0928

HIGH CVSS 8.8 Jul 8, 2025

This vulnerability allows any authenticated Juju controller user to upload malicious agent binaries to any model or the controller itself, bypassing permission checks. This could lead to remote code e...

CVE-2025-53513

HIGH CVSS 8.8 Jul 8, 2025

This vulnerability allows any authenticated user on a Juju controller to upload malicious charms via the /charms endpoint due to insufficient authorization checks. Combined with a Zip Slip vulnerabili...

CVE-2024-7558

HIGH CVSS 8.7 Oct 2, 2024

CVE-2024-7558 allows unprivileged users on the same network namespace to guess the JUJU_CONTEXT_ID authentication secret and access Juju charm information and tools. This affects Juju deployments on b...

CVE-2024-8038

HIGH CVSS 7.9 Oct 2, 2024

This vulnerability allows local users within the same network namespace to access Juju's introspection abstract UNIX domain socket without authentication. This enables denial of service attacks by dis...

CVE-2025-53512

MEDIUM CVSS 6.5 Jul 8, 2025

This vulnerability allows unauthorized users to access the /log endpoint on Juju controllers, exposing debug messages that may contain sensitive information. Anyone running vulnerable Juju controller ...

CVE-2023-0092

MEDIUM CVSS 4.9 Jan 31, 2025

This vulnerability allows authenticated users with read access to the Juju controller model to download arbitrary files from the controller's filesystem through a crafted remote request. It affects Ju...