« Volver al listado

CVE-2024-8038

Estado: AnalizadaMedia (5.5)—

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-8038",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-8038",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-02T13:52:58.112532Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.9,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 5.3,
        "exploitabilityScore": 2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "repo": "https://github.com/juju/juju",
          "vendor": "Canonical Ltd.",
          "product": "Juju",
          "versions": [
            {
              "status": "affected",
              "version": "3.5",
              "lessThan": "3.5.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.4",
              "lessThan": "3.4.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.3",
              "lessThan": "3.3.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.1",
              "lessThan": "3.1.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.9",
              "lessThan": "2.9.51",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "packageName": "juju"
        }
      ]
    }
  ],
  "published": "2024-10-02T11:15:11.853",
  "references": [
    {
      "url": "https://github.com/juju/juju/security/advisories/GHSA-xwgj-vpm9-q2rq",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-8038",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@ubuntu.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-420"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks."
    },
    {
      "lang": "es",
      "value": "Socket de dominio UNIX abstracto de introspección de juju vulnerable. Un socket de dominio UNIX abstracto responsable de la introspección está disponible sin autenticación localmente para los usuarios del espacio de nombres de la red. Esto permite ataques de denegación de servicio."
    }
  ],
  "lastModified": "2026-06-17T08:21:44.377",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "956F1957-34C5-47D9-B922-107963295A1F",
              "versionEndExcluding": "2.9.51"
            },
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32122910-827A-438E-B1DD-42C8E24D7F5D",
              "versionEndExcluding": "3.1.10",
              "versionStartIncluding": "3.1.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA2EB481-D7FF-4A83-B7ED-A6FCE9AE1029",
              "versionEndIncluding": "3.2.4",
              "versionStartIncluding": "3.2.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3C17769-1003-49A2-A87C-003A9E7E81CD",
              "versionEndExcluding": "3.3.7",
              "versionStartIncluding": "3.3"
            },
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6693CCDC-308E-40B3-BC8A-F9A2320A06F9",
              "versionEndExcluding": "3.4.6",
              "versionStartIncluding": "3.4"
            },
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62BC59FA-04DB-4AC3-977D-691ED721171F",
              "versionEndExcluding": "3.5.4",
              "versionStartIncluding": "3.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}