Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, any authenticated user, machine or controller under a Juju controller can modify the resources of an application within the entire controller. This issue has been patched in versions 2.9.56 and 3.6.19.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-245v-p8fj-vwm2 | Juju has a resource poisoning vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Juju
Juju juju |
|
| Vendors & Products |
Juju
Juju juju |
Fri, 03 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, any authenticated user, machine or controller under a Juju controller can modify the resources of an application within the entire controller. This issue has been patched in versions 2.9.56 and 3.6.19. | |
| Title | Juju: Resource poisoning | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-03T15:28:06.191Z
Reserved: 2025-12-15T20:13:34.486Z
Link: CVE-2025-68153
No data.
Status : Received
Published: 2026-04-03T16:16:23.357
Modified: 2026-04-03T16:16:23.357
Link: CVE-2025-68153
No data.
OpenCVE Enrichment
Updated: 2026-04-03T21:15:18Z
Weaknesses
Github GHSA