JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.
oryginał ENCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:HCanonical Juju
APPCanonical< 2.9.513.1.0 – 3.1.10 (bez)3.2.0 – 3.2.4 (bez)3.3.0 – 3.3.7 (bez)3.4 – 3.4.6 (bez)3.5.0 – 3.5.4 (bez)
Powiązane podatności
Canonical Juju — nieuprawniony dostęp do poświadczeń chmury przez Controller facade
Canonical Juju: brak uwierzytelnienia TLS w klastrze Dqlite umożliwia przejęcie bazy danych
Privilege escalation w Juju przez niezabezpieczony UNIX domain socket
Juju is an open source application orchestration engine that enables any application operation on any infrastr...
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correct...