JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine...
Vulnerability Description
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-7558
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Harry Pidcock
- Harry Pidcock
- Mark Esler
References
More from Canonical Ltd.
View All →Affected Vendor
Canonical Ltd.
View all reports →Affected Software
Timeline
CVSS Vectors
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.