Juju controller - Arbitrary file reading vulnerability
Package
Affected versions
>= 2.9.22, < 2.9.38
>= 3.0.0, < 3.0.3
Patched versions
2.9.38
3.0.3
Description
Published to the GitHub Advisory Database
Mar 1, 2023
Reviewed
Mar 1, 2023
Last updated
Mar 22, 2023
Impact
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
Patches
Patched in juju 2.9.38 and juju 3.0.3
juju/juju#ef803e2
Workarounds
Limit read access to the controller model to only trusted users.
References