CVE-2024-9313
HIGHDescription
Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.
Is your site exposed to CVE-2024-9313?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| canonical | authd |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-9313? +
How severe is CVE-2024-9313? +
What products are affected by CVE-2024-9313? +
How do I check if I'm vulnerable to CVE-2024-9313? +
Related Vulnerabilities
MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in …
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - …