CVE-2025-68153 describes a high-severity vulnerability in Juju, an open-source application orchestration engine, affecting versions 2.9 prior to 2.9.56 and 3.6 prior to 3.6.19. This flaw allows any authenticated user, machine, or controller to modify application resources across the entire Juju controller. Rated with a CVSS score of 7.1 (High), it presents a network attack vector with low attack complexity and requires only low privileges, leading to a high integrity impact. There is currently no evidence of active exploitation, nor is public exploit code available, with community discussion limited to a single mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.9, <= 2.9.55CPE matchmatch criteria | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* | ||
>= 3.6, <= 3.6.18CPE matchmatch criteria | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.