CVE-2024-6984: High severity juju vulnerability
An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6984?
CVE-2024-6984 is classified as a medium severity vulnerability due to the potential for local unprivileged attackers to access sensitive data.
How do I fix CVE-2024-6984?
To fix CVE-2024-6984, update to Juju versions 2.9.50 or later, 3.1.9 or later, 3.3.6 or later, 3.4.5 or later, or 3.5.3 or later.
What kind of data can be leaked due to CVE-2024-6984?
CVE-2024-6984 can result in the leakage of sensitive context IDs, allowing access to other sensitive data or relations connected to the local charm.
Who is affected by CVE-2024-6984?
CVE-2024-6984 affects users of Canonical Juju versions prior to the specified secure versions.
What is the impact of CVE-2024-6984 on Juju users?
The impact of CVE-2024-6984 is that local unprivileged attackers may exploit the vulnerability to gain unauthorized access to sensitive data.