Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Juju | Canonical | * | 1.25.12 (including) |
Juju | Canonical | 2.0.0 (including) | 2.0.0 (including) |
Juju | Canonical | 2.0.0-alpha1 (including) | 2.0.0-alpha1 (including) |
Juju | Canonical | 2.0.0-alpha2 (including) | 2.0.0-alpha2 (including) |
Juju | Canonical | 2.0.0-beta1 (including) | 2.0.0-beta1 (including) |
Juju | Canonical | 2.0.0-beta10 (including) | 2.0.0-beta10 (including) |
Juju | Canonical | 2.0.0-beta11 (including) | 2.0.0-beta11 (including) |
Juju | Canonical | 2.0.0-beta12 (including) | 2.0.0-beta12 (including) |
Juju | Canonical | 2.0.0-beta13 (including) | 2.0.0-beta13 (including) |
Juju | Canonical | 2.0.0-beta14 (including) | 2.0.0-beta14 (including) |
Juju | Canonical | 2.0.0-beta15 (including) | 2.0.0-beta15 (including) |
Juju | Canonical | 2.0.0-beta16 (including) | 2.0.0-beta16 (including) |
Juju | Canonical | 2.0.0-beta17 (including) | 2.0.0-beta17 (including) |
Juju | Canonical | 2.0.0-beta18 (including) | 2.0.0-beta18 (including) |
Juju | Canonical | 2.0.0-beta2 (including) | 2.0.0-beta2 (including) |
Juju | Canonical | 2.0.0-beta3 (including) | 2.0.0-beta3 (including) |
Juju | Canonical | 2.0.0-beta4 (including) | 2.0.0-beta4 (including) |
Juju | Canonical | 2.0.0-beta5 (including) | 2.0.0-beta5 (including) |
Juju | Canonical | 2.0.0-beta6 (including) | 2.0.0-beta6 (including) |
Juju | Canonical | 2.0.0-beta7 (including) | 2.0.0-beta7 (including) |
Juju | Canonical | 2.0.0-beta8 (including) | 2.0.0-beta8 (including) |
Juju | Canonical | 2.0.0-beta9 (including) | 2.0.0-beta9 (including) |
Juju | Canonical | 2.0.0-rc1 (including) | 2.0.0-rc1 (including) |
Juju | Canonical | 2.0.0-rc2 (including) | 2.0.0-rc2 (including) |
Juju | Canonical | 2.0.0-rc3 (including) | 2.0.0-rc3 (including) |
Juju | Canonical | 2.0.1 (including) | 2.0.1 (including) |
Juju | Canonical | 2.0.2 (including) | 2.0.2 (including) |
Juju | Canonical | 2.0.3 (including) | 2.0.3 (including) |
Juju | Canonical | 2.1.0 (including) | 2.1.0 (including) |
Juju | Canonical | 2.1.0-beta1 (including) | 2.1.0-beta1 (including) |
Juju | Canonical | 2.1.0-beta2 (including) | 2.1.0-beta2 (including) |
Juju | Canonical | 2.1.0-beta3 (including) | 2.1.0-beta3 (including) |
Juju | Canonical | 2.1.0-beta4 (including) | 2.1.0-beta4 (including) |
Juju | Canonical | 2.1.0-beta5 (including) | 2.1.0-beta5 (including) |
Juju | Canonical | 2.1.0-rc1 (including) | 2.1.0-rc1 (including) |
Juju | Canonical | 2.1.0-rc2 (including) | 2.1.0-rc2 (including) |
Juju | Canonical | 2.1.1 (including) | 2.1.1 (including) |
Juju | Canonical | 2.1.2 (including) | 2.1.2 (including) |
Juju-core | Ubuntu | esm-infra/xenial | * |
Juju-core | Ubuntu | trusty | * |
Juju-core | Ubuntu | upstream | * |
Juju-core | Ubuntu | xenial | * |
Juju-core | Ubuntu | yakkety | * |
Juju-core | Ubuntu | zesty | * |
Juju-core-1 | Ubuntu | esm-apps/xenial | * |
Juju-core-1 | Ubuntu | upstream | * |
Juju-core-1 | Ubuntu | xenial | * |
Juju-core-1 | Ubuntu | yakkety | * |