CVE-2017-9232

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
canonicaljuju
𝑥
≤ 1.25.12
canonicaljuju
2.0.0
canonicaljuju
2.0.0:alpha1
canonicaljuju
2.0.0:alpha2
canonicaljuju
2.0.0:beta1
canonicaljuju
2.0.0:beta10
canonicaljuju
2.0.0:beta11
canonicaljuju
2.0.0:beta12
canonicaljuju
2.0.0:beta13
canonicaljuju
2.0.0:beta14
canonicaljuju
2.0.0:beta15
canonicaljuju
2.0.0:beta16
canonicaljuju
2.0.0:beta17
canonicaljuju
2.0.0:beta18
canonicaljuju
2.0.0:beta2
canonicaljuju
2.0.0:beta3
canonicaljuju
2.0.0:beta4
canonicaljuju
2.0.0:beta5
canonicaljuju
2.0.0:beta6
canonicaljuju
2.0.0:beta7
canonicaljuju
2.0.0:beta8
canonicaljuju
2.0.0:beta9
canonicaljuju
2.0.0:rc1
canonicaljuju
2.0.0:rc2
canonicaljuju
2.0.0:rc3
canonicaljuju
2.0.1
canonicaljuju
2.0.2
canonicaljuju
2.0.3
canonicaljuju
2.1.0
canonicaljuju
2.1.0:beta1
canonicaljuju
2.1.0:beta2
canonicaljuju
2.1.0:beta3
canonicaljuju
2.1.0:beta4
canonicaljuju
2.1.0:beta5
canonicaljuju
2.1.0:rc1
canonicaljuju
2.1.0:rc2
canonicaljuju
2.1.1
canonicaljuju
2.1.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
juju-core
zesty
Fixed 2.0.2-0ubuntu2.1
released
yakkety
Fixed 2.0.2-0ubuntu0.16.10.2
released
xenial
Fixed 2.0.2-0ubuntu0.16.04.2
released
trusty
Fixed 1.25.6-0ubuntu1.14.04.2
released
juju-core-1
zesty
dne
yakkety
Fixed 1.25.6-0ubuntu2.16.10.2
released
xenial
Fixed 1.25.6-0ubuntu1.16.04.2
released
trusty
dne