Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: juju

Found 14 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2024-8037
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): HIGH
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
Vulnerable juju hook tool abstract UNIX domain socket. When combined …

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.

Affected products

juju
  • <3.4.6
  • <2.9.51
  • <3.1.10
  • <3.5.4
  • <3.3.7

Matching in nixpkgs

pkgs.juju

Open source modelling tool for operating software in the cloud

  • nixos-unstable -

pkgs.jujutsu

Git-compatible DVCS that is both simple and powerful

  • nixos-unstable -

pkgs.jujuutils

Utilities around FireWire devices connected to a Linux computer

  • nixos-unstable -
Untriaged
Permalink CVE-2024-7558
8.7 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine …

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.

Affected products

juju
  • <3.4.6
  • <2.9.51
  • <3.1.10
  • <3.5.4
  • <3.3.7

Matching in nixpkgs

pkgs.juju

Open source modelling tool for operating software in the cloud

  • nixos-unstable -

pkgs.jujutsu

Git-compatible DVCS that is both simple and powerful

  • nixos-unstable -

pkgs.jujuutils

Utilities around FireWire devices connected to a Linux computer

  • nixos-unstable -
Untriaged
Permalink CVE-2024-8038
7.9 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): HIGH
created 6 months ago
Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX …

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.

Affected products

juju
  • <3.4.6
  • <2.9.51
  • <3.1.10
  • <3.5.4
  • <3.3.7

Matching in nixpkgs

pkgs.juju

Open source modelling tool for operating software in the cloud

  • nixos-unstable -

pkgs.jujutsu

Git-compatible DVCS that is both simple and powerful

  • nixos-unstable -

pkgs.jujuutils

Utilities around FireWire devices connected to a Linux computer

  • nixos-unstable -
Untriaged
Permalink CVE-2024-6984
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
An issue was discovered in Juju that resulted in the …

An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.

Affected products

juju
  • <3.3.5
  • <2.9.50
  • <3.5.3
  • <3.1.9
  • <3.4.5

Matching in nixpkgs

pkgs.juju

Open source modelling tool for operating software in the cloud

  • nixos-unstable -

pkgs.jujutsu

Git-compatible DVCS that is both simple and powerful

  • nixos-unstable -

pkgs.jujuutils

Utilities around FireWire devices connected to a Linux computer

  • nixos-unstable -