10

CVE-2017-9232

Exploit

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CanonicalJuju Version <= 1.25.12
CanonicalJuju Version2.0.0
CanonicalJuju Version2.0.0 Updatealpha1
CanonicalJuju Version2.0.0 Updatealpha2
CanonicalJuju Version2.0.0 Updatebeta1
CanonicalJuju Version2.0.0 Updatebeta10
CanonicalJuju Version2.0.0 Updatebeta11
CanonicalJuju Version2.0.0 Updatebeta12
CanonicalJuju Version2.0.0 Updatebeta13
CanonicalJuju Version2.0.0 Updatebeta14
CanonicalJuju Version2.0.0 Updatebeta15
CanonicalJuju Version2.0.0 Updatebeta16
CanonicalJuju Version2.0.0 Updatebeta17
CanonicalJuju Version2.0.0 Updatebeta18
CanonicalJuju Version2.0.0 Updatebeta2
CanonicalJuju Version2.0.0 Updatebeta3
CanonicalJuju Version2.0.0 Updatebeta4
CanonicalJuju Version2.0.0 Updatebeta5
CanonicalJuju Version2.0.0 Updatebeta6
CanonicalJuju Version2.0.0 Updatebeta7
CanonicalJuju Version2.0.0 Updatebeta8
CanonicalJuju Version2.0.0 Updatebeta9
CanonicalJuju Version2.0.0 Updaterc1
CanonicalJuju Version2.0.0 Updaterc2
CanonicalJuju Version2.0.0 Updaterc3
CanonicalJuju Version2.0.1
CanonicalJuju Version2.0.2
CanonicalJuju Version2.0.3
CanonicalJuju Version2.1.0
CanonicalJuju Version2.1.0 Updatebeta1
CanonicalJuju Version2.1.0 Updatebeta2
CanonicalJuju Version2.1.0 Updatebeta3
CanonicalJuju Version2.1.0 Updatebeta4
CanonicalJuju Version2.1.0 Updatebeta5
CanonicalJuju Version2.1.0 Updaterc1
CanonicalJuju Version2.1.0 Updaterc2
CanonicalJuju Version2.1.1
CanonicalJuju Version2.1.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 81.61% 0.991
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.