CVE-2024-7558
8.7HIGHJUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an
Publicado: 10/2/2024Actualizado: 8/26/2025
Descripción
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.
Análisis IAImpulsado por IA
Productos Afectados
canonicaljuju
canonicaljuju
canonicaljuju
canonicaljuju
canonicaljuju
canonicaljuju
Referencias
- https://github.com/juju/juju/security/advisories/GHSA-mh98-763h-m9v4ExploitPatchVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-7558Third Party Advisory