CVE-2025-0928

Aliases:GHSA-4vc8-wvhw-m5gvGO-2025-3805
Advisory lineage Upstream: 0 Downstream: 1
Analyzed
Published: 08 Jul 2025, 17:20
Last modified:08 Jul 2025, 17:36

Vulnerability Summary

Overall Risk (default)
medium
46/100
CVSS Score
8.8 HIGH
v3.1 (cve.org)
EPSS Score
2.32% LOW
2% probability +1.94%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

08 Jul 2025, 17:20
Published
Vulnerability first disclosed
08 Jul 2025, 17:36
Last Modified
Vulnerability information updated

Description

In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. This enabled the distribution of poisoned binaries to new or upgraded machines, potentially resulting in remote code execution.

CVSS Metrics

  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 2.32% Percentile: 85%

Techniques & Countermeasures

  • CWE-285Improper Authorization

    The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

  • CWE-434Unrestricted Upload of File with Dangerous Type

    The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Affected Systems

  • canonicaljuju

    ≥ 2.0.0, < 2.9.52 | ≥ 3.0.0, < 3.6.8 | < 2.9.52 | ≥ 3.0, < 3.6.8

  • github.com/jujujuju

    < 0.0.0-20250619215741-4034aa13c7cf | all

References (8)