CVE-2024-7558

HIGH

Juju < 2.9.51 - Unauthenticated Predictable Authentication Secret via JUJU_CONTEXT_ID

Title source: llm
STIX 2.1

Description

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.

References (2)

Core 2
Core References
Exploit, Patch, Vendor Advisory issue-tracking
https://github.com/juju/juju/security/advisories/GHSA-mh98-763h-m9v4
Third Party Advisory issue-tracking
https://www.cve.org/CVERecord?id=CVE-2024-7558

Scores

CVSS v3 8.7
EPSS 0.0050
EPSS Percentile 38.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-340 CWE-337 CWE-335 CWE-330 CWE-1391
Status published
Products (2)
canonical/juju < 2.9.51
juju/juju 0 - 0.0.0-20240826044107-ecd7e2d0e986Go
Published Oct 02, 2024
Tracked Since Feb 18, 2026