CVE-2024-7558 - CVE House
Back to Database
Status published High CVE-2024-7558

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine...

Vulnerability Description

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-7558

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Harry Pidcock
  • Harry Pidcock
  • Mark Esler

Affected Vendor

Canonical Ltd.

View all reports →

Affected Software

Juju
Vulnerable Versions:
3.5, 3.4, 3.3, 3.1, 2.9

Timeline

Official Publish: October 2nd, 2024
Last Modified: October 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.