CVE-2023-0092Path Traversal in LTD Juju

Severity
4.9MEDIUMNVD
EPSS
0.5%
top 34.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31

Description

An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages3 packages

NVDcanonical/juju2.9.222.9.38+1
CVEListV5canonical_ltd/juju2.9.222.9.38+2
Gogithub.com/juju_juju2.9.222.9.38+1

Patches

🔴Vulnerability Details

3
CVEList
CVE-2023-0092: An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controll2025-01-31
OSV
Juju controller - Arbitrary file reading vulnerability2023-03-01
GHSA
Juju controller - Arbitrary file reading vulnerability2023-03-01
CVE-2023-0092 — Path Traversal in Canonical LTD Juju | cvebase