{"id":"GHSA-85qf-6845-m8p2","summary":"Duplicate Advisory: Juju Unprotected Alternate Channel vulnerability","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-xwgj-vpm9-q2rq. This link is maintained to preserve external references.\n\n## Original Description\nVulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.","modified":"2024-10-02T21:55:50Z","published":"2024-10-02T12:30:33Z","withdrawn":"2024-10-02T21:55:50Z","database_specific":{"github_reviewed_at":"2024-10-02T21:55:50Z","nvd_published_at":"2024-10-02T11:15:11Z","cwe_ids":["CWE-420"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/juju/juju/security/advisories/GHSA-xwgj-vpm9-q2rq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8038"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2024-8038"}],"affected":[{"package":{"name":"github.com/juju/juju","ecosystem":"Go","purl":"pkg:golang/github.com/juju/juju"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20241001032836-2af7bd8e310b"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-85qf-6845-m8p2/GHSA-85qf-6845-m8p2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H"}]}