Unprotected Alternate Channel
CVE-2024-8038
Summary
The package juju through 2.9.50, 3.1-beta1 through 3.1.9, 3.2-beta1 through 3.3.6, v3.4-nope through 3.4.5, 3.5-beta1 through 3.5.3, 3.6-beta1 through 4.0-beta4 and after introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available locally to network namespace users without authentication. This enables Denial of Service (DOS) attacks.
- LOW
- LOCAL
- NONE
- UNCHANGED
- NONE
- LOW
- NONE
- HIGH
CWE-420 - Unprotected Alternate Channel
The software protects a primary channel, but it does not use the same level of protection for an alternate channel.
References
Advisory Timeline
- Published