In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical juju |
|
| Vendors & Products |
Canonical
Canonical juju |
Fri, 10 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21. | |
| Title | Juju CloudSpec API could leak senstive information | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-04-10T14:04:30.155Z
Reserved: 2026-04-02T07:07:23.750Z
Link: CVE-2026-5412
Updated: 2026-04-10T14:04:08.292Z
Status : Received
Published: 2026-04-10T13:16:45.780
Modified: 2026-04-10T13:16:45.780
Link: CVE-2026-5412
No data.
OpenCVE Enrichment
Updated: 2026-04-10T14:40:45Z