CVE-2017-9232

EUVD-2017-18170
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
canonicaljuju
𝑥
≤ 1.25.12
canonicaljuju
2.0.0
canonicaljuju
2.0.0:alpha1
canonicaljuju
2.0.0:alpha2
canonicaljuju
2.0.0:beta1
canonicaljuju
2.0.0:beta10
canonicaljuju
2.0.0:beta11
canonicaljuju
2.0.0:beta12
canonicaljuju
2.0.0:beta13
canonicaljuju
2.0.0:beta14
canonicaljuju
2.0.0:beta15
canonicaljuju
2.0.0:beta16
canonicaljuju
2.0.0:beta17
canonicaljuju
2.0.0:beta18
canonicaljuju
2.0.0:beta2
canonicaljuju
2.0.0:beta3
canonicaljuju
2.0.0:beta4
canonicaljuju
2.0.0:beta5
canonicaljuju
2.0.0:beta6
canonicaljuju
2.0.0:beta7
canonicaljuju
2.0.0:beta8
canonicaljuju
2.0.0:beta9
canonicaljuju
2.0.0:rc1
canonicaljuju
2.0.0:rc2
canonicaljuju
2.0.0:rc3
canonicaljuju
2.0.1
canonicaljuju
2.0.2
canonicaljuju
2.0.3
canonicaljuju
2.1.0
canonicaljuju
2.1.0:beta1
canonicaljuju
2.1.0:beta2
canonicaljuju
2.1.0:beta3
canonicaljuju
2.1.0:beta4
canonicaljuju
2.1.0:beta5
canonicaljuju
2.1.0:rc1
canonicaljuju
2.1.0:rc2
canonicaljuju
2.1.1
canonicaljuju
2.1.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
juju-core
trusty
Fixed 1.25.6-0ubuntu1.14.04.2
released
xenial
Fixed 2.0.2-0ubuntu0.16.04.2
released
yakkety
Fixed 2.0.2-0ubuntu0.16.10.2
released
zesty
Fixed 2.0.2-0ubuntu2.1
released
juju-core-1
trusty
dne
xenial
Fixed 1.25.6-0ubuntu1.16.04.2
released
yakkety
Fixed 1.25.6-0ubuntu2.16.10.2
released
zesty
dne