The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/juju/juju(Go) | 0 | 0.0.0-20250619024904-402ff008dcc2 | N/A |
CVSS Metrics