Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2360 | The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that ops passes the secret content as one of the args via CLI. This issue may affect any of the charms that are using: Juju (>=3.0), Juju secrets and not correctly capturing and processing `subprocess.CalledProcessError`. This vulnerability is fixed in 2.15.0. |
Github GHSA |
GHSA-hcmv-jmqh-fjgm | ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command |
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:46:52.414Z
Reserved: 2024-07-15T15:53:28.324Z
Link: CVE-2024-41129
Updated: 2024-08-02T04:46:52.414Z
Status : Deferred
Published: 2024-07-22T15:15:03.710
Modified: 2026-06-17T07:47:20.057
Link: CVE-2024-41129
No data.
OpenCVE Enrichment
No data.
-
CWE-532
Insertion of Sensitive Information into Log File
EUVD
Github GHSA