GHSA-j3hp-pv6v-rgrx
Dashboard / Vulnerabilities / GHSA-j3hp-pv6v-rgrx
GHSA-j3hp-pv6v-rgrx
Published: 13 May 2022Last Modified: 24 Apr 2025
Aliases:
Summary: Juju uses a UNIX domain socket without setting appropriate permissions
Details: Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-9232, https://github.com/juju/juju/commit/0417178a3c2869537860e8b3b5e787ce1732231f, https://bugs.launchpad.net/juju/+bug/1682411, https://github.com/juju/juju, https://www.exploit-db.com/exploits/44023
Affected packages
Package
Name: github.com/juju/juju
Purl: pkg:golang/github.com/juju/juju
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.0.0-20170524231039-0417178a3c28
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
