PT-2024-38763 · Canonical+1 · Juju+1

Harry Pidcock

+4

·

Published

2024-10-02

·

Updated

2025-08-26

·

CVE-2024-8037

CVSS v3.1

6.5

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions: juju versions prior to 2.9.51 juju versions prior to 3.1.10 juju versions prior to 3.3.7 juju versions prior to 3.4.6 juju versions prior to 3.5.4
Description: The juju hook tool's abstract UNIX domain socket is vulnerable. When combined with an attack of JUJU CONTEXT ID, any user on the local system with access to the default network namespace may connect to the /var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.
Recommendations: For versions prior to 2.9.51, update to version 2.9.51 or later. For versions prior to 3.1.10, update to version 3.1.10 or later. For versions prior to 3.3.7, update to version 3.3.7 or later. For versions prior to 3.4.6, update to version 3.4.6 or later. For versions prior to 3.5.4, update to version 3.5.4 or later.

Fix

Improper Access Control

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-8037
GHSA-8V4W-F4R9-7H6X
GHSA-FC27-7PF5-96V3
GO-2024-3174
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Suse
Juju