Executive brief
Juju is an application orchestration engine used to deploy and manage software across various cloud infrastructures. A security flaw allows any authenticated user or machine on the system to modify application resources, such as container images or configuration files, across the entire controller. This could allow an attacker to replace legitimate software with malicious versions, potentially leading to data theft or full system takeover.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Juju's resource handler. The handler used a single authorization check for both 'GET' and 'PUT' operations, requiring only basic authentication as a user, machine, or controller without verifying specific model-level write permissions. An attacker with valid credentials and knowledge of a target's model UUID, application name, and resource name can perform a 'PUT' request to the resource handler path. This allows the attacker to overwrite the resource cache on the controller, effectively poisoning OCI images or file resources used by other applications. The issue is fixed in versions 2.9.56 and 3.6.19 by implementing distinct permission checks for upload operations.
Affected products
- Canonical Juju 2.9 to 2.9.55, 3.6 to 3.6.18
Timeline
- 2025-12-17: other: Fix authored
- 2026-01-20: patched: Fix committed to repository
- 2026-04-01: advisory: Vendor advisory published via GitHub
- 2026-04-03: disclosed: CVE published to NVD