CVE-2024-3250

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/04/2024
Last modified:
26/08/2025

Description

It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:pebble:*:*:*:*:*:go:*:* 1.4.1 (excluding)
cpe:2.3:a:canonical:pebble:*:*:*:*:*:go:*:* 1.4.2 (including) 1.7.3 (excluding)
cpe:2.3:a:canonical:pebble:*:*:*:*:*:go:*:* 1.7.4 (including) 1.10.2 (excluding)