Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fc27-7pf5-96v3

Опубликовано: 02 окт. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Duplicate Advisory: Vulnerable juju hook tool abstract UNIX domain socket

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-8v4w-f4r9-7h6x. This link is maintained to preserve external references.

Original Description

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.

Пакеты

Наименование

github.com/juju/juju

go
Затронутые версииВерсия исправления

< 0.0.0-20241001032836-2af7bd8e310b

0.0.0-20241001032836-2af7bd8e310b

6.5 Medium

CVSS3

6.5 Medium

CVSS3