blob: c23129596a12ecba1eeb9fe9cc6210b807463f55 [file] [log] [blame]
id: GO-2025-3805
modules:
- module: github.com/juju/juju
non_go_versions:
- fixed: 0.0.0-20250619215741-4034aa13c7cf
vulnerable_at: 0.0.0-20250718163602-b0f4af937d12
summary: |-
Juju allows arbitrary executable uploads via authenticated endpoint without
authorization in github.com/juju/juju
cves:
- CVE-2025-0928
ghsas:
- GHSA-4vc8-wvhw-m5gv
references:
- advisory: https://github.com/juju/juju/security/advisories/GHSA-4vc8-wvhw-m5gv
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-0928
- fix: https://github.com/juju/juju/commit/22cdcf6b54c2f371822e1c203d4f341be6c9589e
- fix: https://github.com/juju/juju/commit/311e374cb8d2431032c51fb3fb5c4b0aaaa7196c
- fix: https://github.com/juju/juju/commit/4034aa13c7cf5a37427fcd032925d5d21955b096
- fix: https://github.com/juju/juju/commit/b4176e6e45c2c3c817ab60b39e2d52f9a11a5ddf
source:
id: GHSA-4vc8-wvhw-m5gv
created: 2025-07-21T16:54:06.149066128Z
review_status: UNREVIEWED