← Back

CVE-2024-8037

nvd nist
Published: Oct 2, 2024Modified: Aug 26, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
Exploitability: 1.0 / Impact: 5.5
Source: security@ubuntu.com (Secondary)

Description

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.

Affected (6)

Products: Canonical: Juju
1 product
Juju
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Before 2.9.51
From 3.1.0 to 3.1.10
From 3.2.0 to 3.2.4
From 3.3.0 to 3.3.7
From 3.4 to 3.4.6
From 3.5.0 to 3.5.4

References (2)

Source: security@ubuntu.com
PatchVendor Advisory
Source: security@ubuntu.com
Third Party Advisory

Timeline

No history available yet.