CVE-2024-7558
HIGHDescription
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| canonical | juju |
| canonical | juju |
| canonical | juju |
| canonical | juju |
| canonical | juju |
| canonical | juju |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-7558? +
How severe is CVE-2024-7558? +
What products are affected by CVE-2024-7558? +
How do I check if I'm vulnerable to CVE-2024-7558? +
Related Vulnerabilities
Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated …
A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. …
Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using …
Predictable Seed in Pseudo-Random Number Generator (PRNG) in the firmware for some Intel(R) TDX may allow an authenticated user to …
cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An …
MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function