8.8 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Unauthorized access to Kubernetes secrets in Juju
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee.
References
- https://github.com/juju/juju/security/advisories/GHSA-439w-v2p7-pggc vendor-advisory vdb-entry
Affected products
- <3.6.19
Package maintainers
-
@RealityAnomaly Alex Zero <alex@arctarus.co.uk>
-
@thoughtpolice Austin Seipp <aseipp@pobox.com>
-
@0x4A6F Joachim Ernst <mail-maintainer@0x4A6F.dev>
-
@emilazy Emily <nixpkgs@emily.moe>
-
@bbigras Bruno Bigras <bigras.bruno@gmail.com>