The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.
| Software | From | Fixed in |
|---|---|---|
github.com/juju/juju
|
- | 0.0.0-20250619215741-6356e984b82a |
| canonical / juju | - | 2.9.52 |
| canonical / juju | 3.0.0 | 3.6.8 |