CVE-2024-8038: Canonical Juju
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.
Affected products
- Canonical Juju: before 2.9.51 (fixed in 2.9.51); from 3.1.0, before 3.1.10 (fixed in 3.1.10); from 3.2.0, up to and including 3.2.4; from 3.3, before 3.3.7 (fixed in 3.3.7); from 3.4, before 3.4.6 (fixed in 3.4.6); from 3.5.0, before 3.5.4 (fixed in 3.5.4)
Published 2024-10-02. Last modified 2026-06-17.