Back to Database
Status published
Medium
CVE-2025-53512
Sensitive log retrieval in Juju
Vulnerability Description
The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53512
Credits & Attribution
No credits recorded in the NVD database.
More from Canonical
View All →CVE-2025-6966
Null-pointer dereference in python-apt TagSection.keys()
Medium
6.9
CVE-2025-6224
Key leakage in juju/utils certificates
Medium
6.5
CVE-2025-5689
Improper Permission Management in SSH Session Handling
High
8.5
CVE-2025-5467
Ubuntu Apport Insecure File Permissions Vulnerability
Low
1.9
CVE-2025-5199
LPE on Multipass for macOS
High
7.3
Affected Vendor
Canonical
View all reports →Affected Software
Juju
Vulnerable Versions:
2.0.0, 3.0.0
Timeline
Official Publish:
July 8th, 2025
Last Modified:
July 8th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
MITRE ATT&CK TTPs
T1213
Data from Information Repositories
Collection
T1005
Data from Local System
Collection
T1552
Unsecured Credentials
Credential Access
T1041
Exfiltration Over C2 Channel
Exfiltration
T1190
Exploit Public-Facing Application
Initial Access
T1078
Valid Accounts
Persistence
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1021
Remote Services
Lateral Movement
T1098
Account Manipulation
Defense Evasion