Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Juju — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Juju, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations (CWE) associated with the Juju software ecosystem. It aggregates security vulnerabilities impacting this specific open-source orchestration tool, which is widely used for deploying and managing complex cloud infrastructure. The data collected spans historical records up to the most recently reported and published entries, ensuring a comprehensive view of the product’s security landscape over time. By centralizing this information, the page allows users to track the evolution of security advisories issued by the vendor and community maintainers. Visitors can analyze specific weakness classes to understand the underlying technical flaws, such as injection risks or configuration errors, that have affected Juju. Furthermore, the resource provides a complete vulnerability history for the product, enabling security teams to assess past incidents and evaluate the current risk posture. This structured approach facilitates deeper investigation into how specific vulnerabilities were exploited or mitigated in previous versions. It serves as a reference point for developers and operators seeking to understand the context of reported issues without sifting through scattered announcements. The content is organized to support thorough research into the product’s security track record and to aid in identifying patterns in defect reporting.

Vendor: Ubuntu

CVE IDTitleCVSSSeverityPublished
CVE-2026-5412 Juju CloudSpec API could leak senstive information CWE-285 9.9 Critical2026-04-10
CVE-2026-5774 Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map CWE-362 8.8 -2026-04-10
CVE-2025-68153 Juju: Resource poisoning CWE-863 6.5AIMediumAI2026-04-03
CVE-2025-68152 Juju: Read All Controller Logs From Compromised Workload CWE-863 6.5AIMediumAI2026-04-03
CVE-2026-4370 Improper TLS Client/Server authentication and certificate verification on Database Cluster CWE-295 10.0 Critical2026-04-01
CVE-2026-32694 Insecure Direct Object Reference attack via predictable secret ID in Juju CWE-343 6.6 Medium2026-03-18
CVE-2026-32693 Unauthorized access to Kubernetes secrets in Juju CWE-863 8.8 High2026-03-18
CVE-2026-32692 Unauthorized update of out-of-scope Vault secrets CWE-285 7.6 High2026-03-18
CVE-2026-32691 Timing ownership claim attack on new external back-end secrets CWE-708 5.3 Medium2026-03-18
CVE-2026-1237 Juju 安全漏洞 CWE-672 8.8AIHighAI2026-01-28
CVE-2025-0928 Arbitrary executable upload via authenticated endpoint CWE-285 8.8 High2025-07-08
CVE-2025-53513 Zip slip vulnerability in Juju CWE-24 8.8 High2025-07-08
CVE-2025-53512 Sensitive log retrieval in Juju CWE-200 6.5 Medium2025-07-08
CVE-2023-0092 编号已被CVE保留 4.9 Medium2025-01-31
CVE-2024-8038 Juju 安全漏洞 CWE-420 7.9 High2024-10-02
CVE-2024-8037 Juju 安全漏洞 6.5 Medium2024-10-02
CVE-2024-7558 Juju 安全漏洞 CWE-337 8.7 High2024-10-02
CVE-2024-6984 Juju 安全漏洞 CWE-209 8.8 High2024-07-29
CVE-2015-1316 Juju Joyent provider uploads user's private ssh key by default 5.3 -2019-04-22

All 19 known CVE vulnerabilities affecting Juju with full Chinese analysis, references, and POCs where available.