CVE Vulnerabilities

CVE-2024-9312

Incorrect User Management

Published: Oct 10, 2024 | Modified: Oct 10, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another users ID and gain their privileges.

Weakness

The product does not properly manage a user within its environment.

References