Описание
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.
Ссылки
- ExploitPatchVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
EPSS
8.7 High
CVSS3
8 High
CVSS3
Дефекты
Связанные уязвимости
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju mach ...
JUJU_CONTEXT_ID is a predictable authentication secret
EPSS
8.7 High
CVSS3
8 High
CVSS3