CVE-2017-9232: Juju uses a UNIX domain socket without setting appropriate permissions
(updated )
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
References
Code Behaviors & Features
Detect and mitigate CVE-2017-9232 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →