Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.
2024-10-02T11:15:11.690
2025-08-26T17:48:44.933
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | canonical | juju | < 2.9.51 | Yes |
Application | canonical | juju | < 3.1.10 | Yes |
Application | canonical | juju | ≤ 3.2.4 | Yes |
Application | canonical | juju | < 3.3.7 | Yes |
Application | canonical | juju | < 3.4.6 | Yes |
Application | canonical | juju | < 3.5.4 | Yes |