« Volver al listado

CVE-2024-7558

Estado: AnalizadaAlta (8)—

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-7558",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-7558",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-02T13:58:28.823188Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "repo": "https://github.com/juju/juju",
          "vendor": "Canonical Ltd.",
          "product": "Juju",
          "versions": [
            {
              "status": "affected",
              "version": "3.5",
              "lessThan": "3.5.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.4",
              "lessThan": "3.4.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.3",
              "lessThan": "3.3.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.1",
              "lessThan": "3.1.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.9",
              "lessThan": "2.9.51",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "packageName": "juju"
        }
      ]
    }
  ],
  "published": "2024-10-02T11:15:11.460",
  "references": [
    {
      "url": "https://github.com/juju/juju/security/advisories/GHSA-mh98-763h-m9v4",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-7558",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@ubuntu.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-337"
        },
        {
          "lang": "en",
          "value": "CWE-340"
        },
        {
          "lang": "en",
          "value": "CWE-1391"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-330"
        },
        {
          "lang": "en",
          "value": "CWE-335"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm."
    },
    {
      "lang": "es",
      "value": "JUJU_CONTEXT_ID es un secreto de autenticación predecible. En una máquina Juju (que no sea de Kubernetes) o un contenedor de Juju Charm (en Kubernetes), un usuario sin privilegios en el mismo espacio de nombres de red puede conectarse a un socket de dominio abstracto y adivinar el valor de JUJU_CONTEXT_ID. Esto le otorga al usuario sin privilegios acceso a la misma información y herramientas que el contenedor de Juju Charm."
    }
  ],
  "lastModified": "2026-06-17T08:20:26.893",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "956F1957-34C5-47D9-B922-107963295A1F",
              "versionEndExcluding": "2.9.51"
            },
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32122910-827A-438E-B1DD-42C8E24D7F5D",
              "versionEndExcluding": "3.1.10",
              "versionStartIncluding": "3.1.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1911DB78-6756-49B9-BC0E-90EBBCFA20D9",
              "versionEndExcluding": "3.2.4",
              "versionStartIncluding": "3.2.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90FAD9A5-A5B3-4C53-B609-7BD399F4F6ED",
              "versionEndExcluding": "3.3.7",
              "versionStartIncluding": "3.3.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6693CCDC-308E-40B3-BC8A-F9A2320A06F9",
              "versionEndExcluding": "3.4.6",
              "versionStartIncluding": "3.4"
            },
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62BC59FA-04DB-4AC3-977D-691ED721171F",
              "versionEndExcluding": "3.5.4",
              "versionStartIncluding": "3.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}