JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.
| Software | From | Fixed in |
|---|---|---|
| canonical / juju | - | 2.9.51 |
| canonical / juju | 3.1.0 | 3.1.10 |
| canonical / juju | 3.2.0 | 3.2.4 |
| canonical / juju | 3.3.0 | 3.3.7 |
| canonical / juju | 3.4 | 3.4.6 |
| canonical / juju | 3.5.0 | 3.5.4 |