An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Canonical Juju
cpe:2.3:a:canonical:juju:*:*:*:*:*:go:*:*
|
2.9.22
|
2.9.38
|
|
Canonical Juju
cpe:2.3:a:canonical:juju:*:*:*:*:*:go:*:*
|
3.0.0
|
3.0.3
|