← Back to CVE List

CVE-2024-7558

Published: 2024-10-02T11:15Z
Last Modified: 2024-10-04T13:50Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt