Juju是Canonical Juju开源的一个开源应用程序编排引擎。 Juju存在安全漏洞,该漏洞源于/charms端点授权检查不足,可能导致任意用户上传特制charm,利用Zip Slip漏洞获取机器访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-0928 | 8.8 HIGH | Arbitrary executable upload via authenticated endpoint |
| CVE-2025-53512 | 6.5 MEDIUM | Sensitive log retrieval in Juju |
No comments yet