Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2023-0092
Disclosure Date: January 31, 2025 (last updated January 31, 2025)
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
0
Attacker Value
Unknown
CVE-2024-8038
Disclosure Date: October 02, 2024 (last updated October 02, 2024)
Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.
0
Attacker Value
Unknown
CVE-2024-8037
Disclosure Date: October 02, 2024 (last updated October 02, 2024)
Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.
0
Attacker Value
Unknown
CVE-2024-7558
Disclosure Date: October 02, 2024 (last updated October 02, 2024)
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.
0
Attacker Value
Unknown
CVE-2024-6984
Disclosure Date: July 29, 2024 (last updated September 12, 2024)
An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.
0
Attacker Value
Unknown
Juju Joyent provider uploads user's private ssh key by default
Disclosure Date: April 22, 2019 (last updated November 27, 2024)
Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
0
Attacker Value
Unknown
CVE-2017-9232
Disclosure Date: May 28, 2017 (last updated November 26, 2024)
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
0