CVE-2017-9232: Critical severity Canonical Juju vulnerability
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9232?
CVE-2017-9232 is classified as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2017-9232?
To fix CVE-2017-9232, update Juju to versions 1.25.12, 2.0.4, or 2.1.3 or later that set proper permissions on UNIX domain sockets.
What systems are affected by CVE-2017-9232?
CVE-2017-9232 affects Juju versions prior to 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3.
What is the cause of CVE-2017-9232?
CVE-2017-9232 is caused by Juju using UNIX domain sockets without setting appropriate permissions, allowing unauthorized privilege escalation.
Can I check if my Juju installation is vulnerable to CVE-2017-9232?
Yes, you can check your Juju installation version against the affected versions listed in CVE-2017-9232 to determine if it is vulnerable.