{"id":"CVE-2017-9232","aliases":["GHSA-j3hp-pv6v-rgrx","GO-2025-3639"],"url":"https://o3.security/vulnerability/CVE-2017-9232","summary":"Juju uses a UNIX domain socket without setting appropriate permissions","details":"Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.","published":"2017-05-28T00:29:00.453Z","modified":"2026-08-07T11:31:29.820452721Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"Go","name":"github.com/juju/juju","fixedVersion":"0.0.0-20170524231039-0417178a3c28"}],"fix":null,"references":[{"type":"WEB","url":"https://www.exploit-db.com/exploits/44023/"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/98737"},{"type":"REPORT","url":"https://bugs.launchpad.net/juju/+bug/1682411"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:29.820452721Z"}}