CVE-2024-8038 - CVE House
Back to Database
Status published High CVE-2024-8038

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX...

Vulnerability Description

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8038

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Harry Pidcock
  • Harry Pidcock
  • Mark Esler

Affected Vendor

Canonical Ltd.

View all reports →

Affected Software

Juju
Vulnerable Versions:
3.5, 3.4, 3.3, 3.1, 2.9

Timeline

Official Publish: October 2nd, 2024
Last Modified: October 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.