VDB

CVE-2024-8038

CVE-2024-8038 PUBLISHED CVSS 7.900000095367432 HIGH

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.

EPSS 0.21% · 11.5th percentile

Risk Scores

CVSS 3.1
7.900000095367432
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
EPSS Score
0.21%
11.5th percentile

Affected Products

VendorProductVersions
github.comjuju/juju0, 0
canonicaljuju3.4, 3.5.0, 3.2.0
Canonical Ltd.Juju3.3, 3.1, 2.9

Timeline

  • Oct 2, 2024 CVE Published
  • Oct 2, 2024 PoC Published
  • Oct 3, 2024 EPSS Score
  • Oct 5, 2024 Coalition ESS Score
  • Oct 22, 2024 EPSS Score
  • Nov 1, 2024 Coalition ESS Score
  • Nov 10, 2024 EPSS Score
  • Nov 29, 2024 EPSS Score
  • Dec 19, 2024 EPSS Score
  • Jan 8, 2025 EPSS Score
  • Jan 27, 2025 EPSS Score
  • Feb 15, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›