CVE-2017-9232: Canonical Juju

Critical severity, CVSS 9.8. EPSS: 48.5% chance of exploitation in the next 30 days.

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.

Affected products

  • Canonical Juju: up to and including 1.25.12; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.1.0 only; …

Published 2017-05-28. Last modified 2026-06-17.