Vulnerable juju hook tool abstract UNIX domain socket
Package
Affected versions
< 0.0.0-20240820065804-2f2ec128ef5a
Patched versions
0.0.0-20240820065804-2f2ec128ef5a
Description
Published to the GitHub Advisory Database
Oct 3, 2024
Reviewed
Oct 3, 2024
Last updated
Oct 9, 2024
Impact
When combined with an attack of
JUJU_CONTEXT_ID
, any user on the local system with access to the default network namespace may connect to the@/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket
and perform actions that are normally reserved to a juju charm.Patches
Patch: juju/juju@2f2ec12
Patched in:
Workarounds
No workarounds available.
References
GHSA-mh98-763h-m9v4
https://github.com/juju/juju/blob/725800953aaa29dbeda4f806097bf838e61644dd/worker/uniter/paths.go#L222
References