CVE-2017-9232

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/05/2017
Last modified:
20/04/2025

Description

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* 1.25.12 (including)
cpe:2.3:a:canonical:juju:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta10:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta11:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta12:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta13:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta14:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta15:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta16:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta17:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta18:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:2.0.0:beta2:*:*:*:*:*:*