CVE-2015-1316

CWE-3204 documents4 sources
Severity
7.5HIGH
EPSS
0.4%
top 41.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 22
Latest updateMay 24

Description

Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9

Affected Packages3 packages

Ubuntujuju-core< 1.24.7-0ubuntu1~14.04.1
CVEListV5ubuntu/jujuJuju Core1.25.5
NVDcanonical/juju< 1.25.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c7j6-fjmf-wjwc: Juju Core's Joyent provider before version 12022-05-24
OSV
CVE-2015-1316: Juju Core's Joyent provider before version 12019-04-22
CVEList
Juju Joyent provider uploads user's private ssh key by default2019-04-22
CVE-2015-1316 (HIGH CVSS 7.5) | Juju Core's Joyent provider before | cvebase.io