Vulnerabilities
Vulnerable Software
Canonical:  >> Juju  >> 2.1.3  Security Vulnerabilities
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.
CVSS Score
8.7
EPSS Score
0.0
Published
2024-10-02
Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.
CVSS Score
6.5
EPSS Score
0.0
Published
2024-10-02
Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.
CVSS Score
7.9
EPSS Score
0.0
Published
2024-10-02


Contact Us

Shodan ® - All rights reserved