CVE-2017-9232

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-9232
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9232.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-9232
Related
Published
2017-05-28T00:29:00Z
Modified
2025-01-14T07:19:49.472783Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.

References

Affected packages

Git / github.com/juju/juju

Affected ranges

Type
GIT
Repo
https://github.com/juju/juju
Events

Affected versions

juju-1.*

juju-1.19.3
juju-1.19.4
juju-1.21-alpha1
juju-1.21-alpha2
juju-1.21-alpha3
juju-1.24-alpha1
juju-1.24-beta1
juju-1.24-beta2
juju-1.24-beta3
juju-1.24-beta4
juju-1.24-beta5
juju-1.24-beta6
juju-1.25-alpha1
juju-1.25-beta1
juju-1.25.0
juju-1.26-alpha1
juju-1.26-alpha2
juju-1.26-alpha3

juju-2.*

juju-2.0-alpha1
juju-2.0-alpha2
juju-2.0-beta1
juju-2.0-beta10
juju-2.0-beta11
juju-2.0-beta12
juju-2.0-beta13
juju-2.0-beta14
juju-2.0-beta15
juju-2.0-beta16
juju-2.0-beta17
juju-2.0-beta18
juju-2.0-beta2
juju-2.0-beta3
juju-2.0-beta4
juju-2.0-beta5
juju-2.0-beta6
juju-2.0-beta7
juju-2.0-beta8
juju-2.0-beta9
juju-2.0-rc1
juju-2.0-rc2
juju-2.0-rc3
juju-2.0.0
juju-2.1-beta1
juju-2.1-beta2
juju-2.1-beta3
juju-2.1-beta4
juju-2.1-beta5
juju-2.1-rc1
juju-2.1-rc2
juju-2.1.0