CVE-2024-8038

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*

History

26 Aug 2025, 17:44

Type Values Removed Values Added
References () https://github.com/juju/juju/security/advisories/GHSA-xwgj-vpm9-q2rq - () https://github.com/juju/juju/security/advisories/GHSA-xwgj-vpm9-q2rq - Patch, Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2024-8038 - () https://www.cve.org/CVERecord?id=CVE-2024-8038 - Third Party Advisory
CWE NVD-CWE-noinfo
First Time Canonical
Canonical juju
CPE cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) Socket de dominio UNIX abstracto de introspección de juju vulnerable. Un socket de dominio UNIX abstracto responsable de la introspección está disponible sin autenticación localmente para los usuarios del espacio de nombres de la red. Esto permite ataques de denegación de servicio.

02 Oct 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-02 11:15

Updated : 2025-08-26 17:44


NVD link : CVE-2024-8038

Mitre link : CVE-2024-8038

CVE.ORG link : CVE-2024-8038


JSON object : View

Products Affected

canonical

  • juju
CWE
CWE-420

Unprotected Alternate Channel

NVD-CWE-noinfo