blob: 8d93034b03fa211255c95e3f5b98a8c4a6fd641a [file] [log] [blame]
id: GO-2025-3804
modules:
- module: github.com/juju/juju
versions:
- fixed: 0.0.0-20250619215741-6356e984b82a
summary: Juju zip slip vulnerability via authenticated endpoint in github.com/juju/juju
cves:
- CVE-2025-53513
ghsas:
- GHSA-24ch-w38v-xmh8
references:
- advisory: https://github.com/juju/juju/security/advisories/GHSA-24ch-w38v-xmh8
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-53513
- fix: https://github.com/juju/juju/commit/6356e984b82a4a7b9771ff5e51e297ad62f3b405
- fix: https://github.com/juju/juju/commit/ff39557a137c0e95d4cd3553b0f19c859c6f5d8e
- web: https://drive.google.com/file/d/1pHRNiaA8LyMVJYwIyTqelsqJ9FmImDf0/view
- web: https://github.com/juju/juju/blob/3.6/apiserver/apiserver.go#L754
- web: https://github.com/juju/juju/blob/3.6/apiserver/apiserver.go#L897
- web: https://github.com/juju/juju/blob/3.6/apiserver/apiserver.go#L990
notes:
- fix: 'github.com/juju/juju: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
source:
id: GHSA-24ch-w38v-xmh8
created: 2025-07-21T16:55:10.919538662Z
review_status: UNREVIEWED