PT-2017-18797 · Canonical · Juju+1
David Ames
+2
·
Published
2017-05-26
·
Updated
2025-04-26
·
CVE-2017-9232
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Juju versions prior to 1.25.12
Juju versions 2.0.x prior to 2.0.4
Juju versions 2.1.x prior to 2.1.3
Description
The issue allows for privilege escalation by users on the system to root due to the use of a UNIX domain socket without appropriate permissions.
Recommendations
For versions prior to 1.25.12, update to version 1.25.12 or later.
For versions 2.0.x prior to 2.0.4, update to version 2.0.4 or later.
For versions 2.1.x prior to 2.1.3, update to version 2.1.3 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Juju
Ubuntu