Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20670 | Juju zip slip vulnerability via authenticated endpoint |
Github GHSA |
GHSA-24ch-w38v-xmh8 | Juju zip slip vulnerability via authenticated endpoint |
Thu, 08 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* |
Tue, 26 Aug 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:canonical:juju:*:*:*:*:*:go:*:* |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm. | |
| Title | Zip slip vulnerability in Juju | |
| Weaknesses | CWE-24 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2025-07-09T14:00:10.613Z
Reserved: 2025-07-02T08:52:42.037Z
Link: CVE-2025-53513
Updated: 2025-07-09T14:00:00.646Z
Status : Analyzed
Published: 2025-07-08T17:16:04.593
Modified: 2026-01-08T11:51:23.900
Link: CVE-2025-53513
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:47:14Z
EUVD
Github GHSA