CVE-2024-6984: Canonical Juju

Low severity, CVSS 3.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.

Affected products

  • Canonical Juju: from 2.9, before 2.9.50 (fixed in 2.9.50); from 3.1, before 3.1.9 (fixed in 3.1.9); from 3.3, before 3.3.6 (fixed in 3.3.6); from 3.4, before 3.4.5 (fixed in 3.4.5); from 3.5, before 3.5.3 (fixed in 3.5.3)

Published 2024-07-29. Last modified 2026-06-17.