Vulnerability DatabaseGHSA-6vjm-54vp-mxhx

GHSA-6vjm-54vp-mxhx
vulnerability analysis and mitigation

Overview

An issue was discovered in Juju (CVE-2024-6984) that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm. The vulnerability affects multiple versions of Juju including versions from 2.9.0 to 2.9.50, 3.1.0 to 3.1.9, 3.3.0 to 3.3.6, 3.4.0 to 3.4.5, and 3.5.0 to 3.5.3. This vulnerability was discovered in July 2024 and patched versions were released shortly after (GitHub Advisory, NVD).

Technical details

The vulnerability stems from overly broad permissions on /var/lib/juju/ directory and the leakage of sensitive context ID in error messages. When a hook is executing, the error message reveals the context ID, which can then be used by an unprivileged user to access sensitive information. The vulnerability is tracked as CWE-209 (Generation of Error Message Containing Sensitive Information) and has received a CVSS v3.1 base score of 8.8 (High) with vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (GitHub Advisory).

Impact

The vulnerability allows an unprivileged user to access any secrets available via hook tools such as config, relation data, and secrets. This includes sensitive information like private keys, passwords, and other confidential data accessible to the local charm. A single compromised host in Juju may provide arbitrary access and potentially even remote access to target applications, enabling privilege abuse and escalation in the environment (GitHub Advisory).

Exploitability

The vulnerability can be exploited by any unprivileged user on a node running a charm. The attack involves running a bash loop attempting to execute hook tools while waiting for another hook to execute. When this occurs, the error message reveals the context ID, which can then be used to access sensitive data. The exploit has been demonstrated to work in both local environments and potentially in Kubernetes deployments (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in versions 2.9.50, 3.1.9, 3.3.6, 3.4.5, and 3.5.3. The fix involves removing the context ID from error messages and limiting the permissions within /var/lib/juju to root-only access. Users are advised to upgrade to the patched versions to prevent unauthorized access to sensitive data (GitHub Advisory, Patch).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management