Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-7558

Опубликовано: 02 окт. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 8.7

Описание

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.

РелизСтатусПримечание
snap

released

3.5.4
upstream

released

3.5.4

Показывать по

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
nvd
почти 2 года назад

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.

CVSS3: 8.7
debian
почти 2 года назад

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju mach ...

CVSS3: 8.7
github
почти 2 года назад

JUJU_CONTEXT_ID is a predictable authentication secret

8.7 High

CVSS3