CVE-2017-9232 PUBLISHED

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.

EPSS 81.60% · 99.2th percentile

Risk Scores

EPSS Score
81.60%
99.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSjuju-core0, 1.24.6-0ubuntu3, 1.25.0-0ubuntu1
Ubuntu:16.04:LTSjuju-core-10, 1.25.4-0ubuntu5, 1.25.6-0ubuntu1.16.04.1
Ubuntu:14.04:LTSjuju-core1.18.4+dfsg-0ubuntu0.14.04.1, 1.20.11-0ubuntu0.14.04.1, 1.22.8-0ubuntu1~14.04.1

Timeline

References

Open in Interactive Console →