Skip to main content

Unprotected Alternate Channel

CVE-2024-8038

Severity Medium
Score 6.2/10

Summary

The package juju through 2.9.50, 3.1-beta1 through 3.1.9, 3.2-beta1 through 3.3.6, v3.4-nope through 3.4.5, 3.5-beta1 through 3.5.3, 3.6-beta1 through 4.0-beta4 and after introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available locally to network namespace users without authentication. This enables Denial of Service (DOS) attacks.

  • LOW
  • LOCAL
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • NONE
  • HIGH

CWE-420 - Unprotected Alternate Channel

The software protects a primary channel, but it does not use the same level of protection for an alternate channel.

Advisory Timeline

  • Published