
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in Juju (CVE-2024-6984) that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm. The vulnerability affects multiple versions of Juju including versions from 2.9.0 to 2.9.50, 3.1.0 to 3.1.9, 3.3.0 to 3.3.6, 3.4.0 to 3.4.5, and 3.5.0 to 3.5.3. This vulnerability was discovered in July 2024 and patched versions were released shortly after (GitHub Advisory, NVD).
The vulnerability stems from overly broad permissions on /var/lib/juju/ directory and the leakage of sensitive context ID in error messages. When a hook is executing, the error message reveals the context ID, which can then be used by an unprivileged user to access sensitive information. The vulnerability is tracked as CWE-209 (Generation of Error Message Containing Sensitive Information) and has received a CVSS v3.1 base score of 8.8 (High) with vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (GitHub Advisory).
The vulnerability allows an unprivileged user to access any secrets available via hook tools such as config, relation data, and secrets. This includes sensitive information like private keys, passwords, and other confidential data accessible to the local charm. A single compromised host in Juju may provide arbitrary access and potentially even remote access to target applications, enabling privilege abuse and escalation in the environment (GitHub Advisory).
The vulnerability can be exploited by any unprivileged user on a node running a charm. The attack involves running a bash loop attempting to execute hook tools while waiting for another hook to execute. When this occurs, the error message reveals the context ID, which can then be used to access sensitive data. The exploit has been demonstrated to work in both local environments and potentially in Kubernetes deployments (GitHub Advisory).
The vulnerability has been patched in versions 2.9.50, 3.1.9, 3.3.6, 3.4.5, and 3.5.3. The fix involves removing the context ID from error messages and limiting the permissions within /var/lib/juju to root-only access. Users are advised to upgrade to the patched versions to prevent unauthorized access to sensitive data (GitHub Advisory, Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."