Juju

Vendor:

First CVE: May 28, 2017 · Active for 9 years

19
Total CVEs
More Total CVEs than 95% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Juju over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 2017
9 years ago
Most Recent CVE
Apr 10, 2026
109 days ago

CVE Severity & Scoring

Juju19 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local3 (15.8%)
Network15 (78.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low15 (78.9%)
High4 (21.1%)
Unknown0 (0.0%)
User Interaction
None19 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low13 (68.4%)
High3 (15.8%)
None3 (15.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the sys
May 28, 20179.876NOYES
A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS clie
Apr 1, 202610.035NONO
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead
Mar 18, 20268.829NONO
In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud cr
Apr 10, 20266.526NONO
Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service o
Apr 10, 20266.424NONO
Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From ve
Apr 3, 20266.524NONO
In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret t
Mar 18, 20266.623NONO
In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verif
Jul 8, 20258.823NONO
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespa
Oct 2, 20248.023NONO
An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized
Mar 18, 20266.522NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.3% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Juju

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.1.219.848.5%01
2.1.119.848.5%01
2.1.019.848.5%01
2.0.319.848.5%01
2.0.219.848.5%01
2.0.119.848.5%01
2.0.019.848.5%01