CVE-2023-0092

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Jan 31, 2025
Updated: Feb 7, 2025
CWE ID 22

Summary

CVE-2023-0092 is a vulnerability affecting the Juju controller that allows authenticated users with read access to make a remote request and download arbitrary files from the controller's filesystem. This issue poses a potential security risk as it enables unauthorized access to sensitive files, potentially leading to data breaches or system compromises. Users are recommended to update their Juju controllers to the latest version to mitigate this vulnerability. Authenticated users should also be granted access on a need-to-have basis to prevent potential misuse of this vulnerability. It is imperative to implement strong access control measures and regularly monitor system logs for any suspicious activity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share