An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://github.com/juju/juju/commit/da929676853092a29ddf8d589468cf85ba3efaf2 | patch |
https://github.com/juju/juju/security/advisories/GHSA-6vjm-54vp-mxhx | vendor advisory issue tracking exploit |
https://www.cve.org/CVERecord?id=CVE-2024-6984 | third party advisory issue tracking |