CVE-2023-0092

Publication date 31 January 2025

Last updated 31 January 2025


Ubuntu priority

An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.

Read the notes from the security team

Status

Package Ubuntu Release Status
juju-core 24.10 oracular Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
20.04 LTS focal Not in release
16.04 LTS xenial
Not affected

Notes


rodrigo-zaiden

affects juju snap juju-core package in archive is not affected

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
juju-core