Description
Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.
Published: 2024-10-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-3000 Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.
Github GHSA Github GHSA GHSA-8v4w-f4r9-7h6x Vulnerable juju hook tool abstract UNIX domain socket
History

Tue, 26 Aug 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical juju
CPEs cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
Vendors & Products Canonical
Canonical juju

Fri, 01 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276

Wed, 02 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Oct 2024 10:30:00 +0000

Type Values Removed Values Added
Description Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2024-11-01T15:31:40.233Z

Reserved: 2024-08-21T00:45:34.399Z

Link: CVE-2024-8037

cve-icon Vulnrichment

Updated: 2024-10-02T13:57:28.291Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-02T11:15:11.690

Modified: 2025-08-26T17:48:44.933

Link: CVE-2024-8037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses