Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v4w-f4r9-7h6x

Опубликовано: 03 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.2
CVSS3: 6.5

Описание

Vulnerable juju hook tool abstract UNIX domain socket

Impact

When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.

Patches

Patch: https://github.com/juju/juju/commit/2f2ec128ef5a8ca81fc86ae79cfcdbab0007c206 Patched in:

  • 3.5.4
  • 3.4.6
  • 3.3.7
  • 3.1.10
  • 2.9.51

Workarounds

No workarounds available.

References

GHSA-mh98-763h-m9v4 https://github.com/juju/juju/blob/725800953aaa29dbeda4f806097bf838e61644dd/worker/uniter/paths.go#L222

Пакеты

Наименование

github.com/juju/juju

go
Затронутые версииВерсия исправления

< 0.0.0-20240820065804-2f2ec128ef5a

0.0.0-20240820065804-2f2ec128ef5a

EPSS

Процентиль: 21%
0.0007
Низкий

6.2 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.

CVSS3: 6.5
nvd
больше 1 года назад

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.

CVSS3: 6.5
debian
больше 1 года назад

Vulnerable juju hook tool abstract UNIX domain socket. When combined w ...

suse-cvrf
больше 1 года назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 21%
0.0007
Низкий

6.2 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-284