Juju是Canonical Juju开源的一个开源应用程序编排引擎。 Juju 3.6.18及之前版本存在安全漏洞,该漏洞源于密钥管理子系统存在竞争条件,可能导致经过身份验证的单位代理获取新初始化密钥的所有权并读取其内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32693 | 8.8 HIGH | Unauthorized access to Kubernetes secrets in Juju |
| CVE-2026-32692 | 7.6 HIGH | Unauthorized update of out-of-scope Vault secrets |
| CVE-2026-32694 | 6.6 MEDIUM | Insecure Direct Object Reference attack via predictable secret ID in Juju |
No comments yet