Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8037


Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.


Published

2024-10-02T11:15:11.690

Last Modified

2025-08-26T17:48:44.933

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application canonical juju < 2.9.51 Yes
Application canonical juju < 3.1.10 Yes
Application canonical juju ≤ 3.2.4 Yes
Application canonical juju < 3.3.7 Yes
Application canonical juju < 3.4.6 Yes
Application canonical juju < 3.5.4 Yes

References