High severityNVD Advisory· Published Jul 8, 2025· Updated Jul 9, 2025
Zip slip vulnerability in Juju
CVE-2025-53513
Description
The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/juju/jujuGo | < 0.0.0-20250619215741-6356e984b82a | 0.0.0-20250619215741-6356e984b82a |
Affected products
3- ghsa-coords2 versions
< 0.0.0-20250619215741-6356e984b82a+ 1 more
- (no CPE)range: < 0.0.0-20250619215741-6356e984b82a
- (no CPE)range: < 0.0.20250730T213748-1.1
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-24ch-w38v-xmh8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-53513ghsaADVISORY
- drive.google.com/file/d/1pHRNiaA8LyMVJYwIyTqelsqJ9FmImDf0/viewghsaWEB
- github.com/juju/juju/blob/3.6/apiserver/apiserver.goghsaWEB
- github.com/juju/juju/blob/3.6/apiserver/apiserver.goghsaWEB
- github.com/juju/juju/blob/3.6/apiserver/apiserver.goghsaWEB
- github.com/juju/juju/commit/6356e984b82a4a7b9771ff5e51e297ad62f3b405ghsaWEB
- github.com/juju/juju/commit/ff39557a137c0e95d4cd3553b0f19c859c6f5d8eghsaWEB
- github.com/juju/juju/security/advisories/GHSA-24ch-w38v-xmh8ghsaWEB
- pkg.go.dev/vuln/GO-2025-3804ghsaWEB
News mentions
0No linked articles in our index yet.