Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3000 | Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm. |
Github GHSA |
GHSA-8v4w-f4r9-7h6x | Vulnerable juju hook tool abstract UNIX domain socket |
Tue, 26 Aug 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical juju |
|
| CPEs | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Canonical
Canonical juju |
Fri, 01 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-276 |
Wed, 02 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Oct 2024 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2024-11-01T15:31:40.233Z
Reserved: 2024-08-21T00:45:34.399Z
Link: CVE-2024-8037
Updated: 2024-10-02T13:57:28.291Z
Status : Analyzed
Published: 2024-10-02T11:15:11.690
Modified: 2025-08-26T17:48:44.933
Link: CVE-2024-8037
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA