CVE-2025-68153

Source
https://cve.org/CVERecord?id=CVE-2025-68153
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68153.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-68153
Aliases
Downstream
Related
Published
2026-04-03T15:28:06Z
Modified
2026-08-12T03:51:46Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Juju: Resource poisoning
Details

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, any authenticated user, machine or controller under a Juju controller can modify the resources of an application within the entire controller. This issue has been patched in versions 2.9.56 and 3.6.19.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68153.json"
}
References

Affected packages

Git / github.com/juju/juju

Affected ranges

Type
GIT
Repo
https://github.com/juju/juju
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.9"
        },
        {
            "last_affected": "2.9.55"
        },
        {
            "introduced": "3.6"
        },
        {
            "last_affected": "3.6.18"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

Other
juju-
juju-2.*
juju-2.9.0
juju-2.9.1
juju-2.9.10
juju-2.9.11
juju-2.9.12
juju-2.9.13
juju-2.9.14
juju-2.9.15
juju-2.9.16
juju-2.9.17
juju-2.9.18
juju-2.9.19
juju-2.9.2
juju-2.9.20
juju-2.9.21
juju-2.9.22
juju-2.9.23
juju-2.9.24
juju-2.9.25
juju-2.9.26
juju-2.9.27
juju-2.9.28
juju-2.9.29
juju-2.9.3
juju-2.9.30
juju-2.9.31
juju-2.9.32
juju-2.9.33
juju-2.9.34
juju-2.9.35
juju-2.9.36
juju-2.9.37
juju-2.9.38
juju-2.9.39
juju-2.9.4
juju-2.9.40
juju-2.9.41
juju-2.9.42
juju-2.9.43
juju-2.9.44
juju-2.9.5
juju-2.9.6
juju-2.9.7
juju-2.9.8
juju-2.9.9
v2.*
v2.9.45
v2.9.46
v2.9.47
v2.9.48
v2.9.49
v2.9.53
v2.9.54
v2.9.55

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68153.json"