Vulnerability Details CVE-2017-9232
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.747
EPSS Ranking 98.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2017-9232
-
cpe:2.3:a:canonical:juju:1.25.12
-
cpe:2.3:a:canonical:juju:1.25.5
-
cpe:2.3:a:canonical:juju:2.0.0
-
cpe:2.3:a:canonical:juju:2.0.1
-
cpe:2.3:a:canonical:juju:2.0.2
-
cpe:2.3:a:canonical:juju:2.0.3
-
cpe:2.3:a:canonical:juju:2.1.0
-
cpe:2.3:a:canonical:juju:2.1.1
-
cpe:2.3:a:canonical:juju:2.1.2