CVE-2024-6984

CWE-2093 documents3 sources
Severity
3.8LOW
EPSS
0.1%
top 67.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 29
Latest updateAug 6

Description

An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages2 packages

NVDcanonical/juju2.92.9.50+4
CVEListV5canonical_ltd./juju3.53.5.3+4

Patches

🔴Vulnerability Details

2
OSV
CVE-2024-6984 in github.com/juju/juju2024-08-06
CVEList
CVE-2024-6984: An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sens2024-07-29
CVE-2024-6984 (LOW CVSS 3.8) | An issue was discovered in Juju tha | cvebase.io