Juju是Canonical Juju开源的一个开源应用程序编排引擎。 Juju存在安全漏洞,该漏洞源于同一网络命名空间中的非特权用户可以连接到抽象域套接字并猜测JUJU_CONTEXT_ID值,从而访问与juju charm相同的信息和工具。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Canonical Ltd. | Juju | 3.5 ~ 3.5.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-8038 | 7.9 HIGH | Juju 安全漏洞 |
| CVE-2024-8037 | 6.5 MEDIUM | Juju 安全漏洞 |
No comments yet