The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that ops passes the secret content as one of the args via CLI. This issue may affect any of the charms that are using: Juju (>=3.0), Juju secrets and not correctly capturing and processing `subprocess.CalledProcessError`. This vulnerability is fixed in 2.15.0.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-07-22T14:20:08.920Z
Updated: 2024-08-02T04:46:52.414Z
Reserved: 2024-07-15T15:53:28.324Z
Link: CVE-2024-41129
Vulnrichment
Updated: 2024-08-02T04:46:52.414Z
NVD
Status : Awaiting Analysis
Published: 2024-07-22T15:15:03.710
Modified: 2024-07-24T12:55:13.223
Link: CVE-2024-41129
Redhat
No data.