CVE-2024-8037
02.10.2024, 11:15
Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | juju | 𝑥 < 2.9.51 |
canonical | juju | 3.1.0 ≤ 𝑥 < 3.1.10 |
canonical | juju | 3.2.0 ≤ 𝑥 ≤ 3.2.4 |
canonical | juju | 3.3.0 ≤ 𝑥 < 3.3.7 |
canonical | juju | 3.4 ≤ 𝑥 < 3.4.6 |
canonical | juju | 3.5.0 ≤ 𝑥 < 3.5.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration