CVE Vulnerabilities

CVE-2024-10963

Improper Authentication

Published: Nov 07, 2024 | Modified: Feb 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 8RedHatpam-0:1.3.1-36.el8_10*
Red Hat Enterprise Linux 9RedHatpam-0:1.5.1-22.el9_5*
Red Hat Enterprise Linux 9RedHatpam-0:1.5.1-22.el9_5*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatpam-0:1.5.1-23.el9_4*
Red Hat OpenShift Container Platform 4.16RedHatrhcos-416.94.202411261619-0*
Red Hat OpenShift Container Platform 4.17RedHatrhcos-417.94.202411261220-0*
Red Hat OpenShift AI 2.16RedHatrhoai/odh-dashboard-rhel8:sha256:c2a79db6d2ba9c313640149a55f306e8aa4dc36f3cc24bf554c025503b013644*
PamUbuntudevel*
PamUbuntunoble*
PamUbuntuoracular*
PamUbuntuplucky*
PamUbuntutrusty/esm*
PamUbuntuupstream*

Potential Mitigations

References