First published: Wed Jan 28 2015(Updated: )
Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Juju | <1.25.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1316 has a moderate severity as it involves the exposure of private SSH keys.
To fix CVE-2015-1316, upgrade to Juju Core version 1.25.5 or later.
CVE-2015-1316 affects Juju Core's Joyent provider prior to version 1.25.5.
CVE-2015-1316 describes a vulnerability where Juju Core's Joyent provider uploads the user's private SSH key.
No, CVE-2015-1316 is not a risk in Juju versions 1.25.5 and above where the vulnerability has been addressed.