CVE-2015-1316: Juju Joyent provider uploads user's private ssh key by default
Published Apr 22, 2019
·Updated
Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
Affected Software
1 affected component
Canonical Juju<1.25.5
Remediation
Event History
Apr 22, 2019
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-1316?
CVE-2015-1316 has a moderate severity as it involves the exposure of private SSH keys.
2
How do I fix CVE-2015-1316?
To fix CVE-2015-1316, upgrade to Juju Core version 1.25.5 or later.
3
What systems are affected by CVE-2015-1316?
CVE-2015-1316 affects Juju Core's Joyent provider prior to version 1.25.5.
4
What vulnerability does CVE-2015-1316 describe?
CVE-2015-1316 describes a vulnerability where Juju Core's Joyent provider uploads the user's private SSH key.
5
Is CVE-2015-1316 still a risk in the latest Juju versions?
No, CVE-2015-1316 is not a risk in Juju versions 1.25.5 and above where the vulnerability has been addressed.