Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.
| Software | From | Fixed in |
|---|---|---|
| canonical / juju | - | 2.9.51 |
| canonical / juju | 3.1.0 | 3.1.10 |
| canonical / juju | 3.2.0 | 3.2.4.x |
| canonical / juju | 3.3.0 | 3.3.7 |
| canonical / juju | 3.4 | 3.4.6 |
| canonical / juju | 3.5.0 | 3.5.4 |