CVE-2024-9313
published 2024-10-03CVE-2024-9313: Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation…
PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.58%
43.7th percentile
Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | authd | < 0.3.5 | 0.3.5 |
| canonical_ltd | authd | < 0.3.5 | 0.3.5 |
| github.com | ubuntu_authd | >= 0 < 0.0.0-20240930103526-63e527496b01 | 0.0.0-20240930103526-63e527496b01 |
| github.com | ubuntu_authd | >= 0 < 0.3.5 | 0.3.5 |
| github.com | ubuntu_authd | >= 0.1.0 < 0.3.5 | 0.3.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
PAM module may allow accessing with the credentials of another user in github.com/ubuntu/authd
osv·2024-10-09
CVE-2024-9313 PAM module may allow accessing with the credentials of another user in github.com/ubuntu/authd
PAM module may allow accessing with the credentials of another user in github.com/ubuntu/authd
PAM module may allow accessing with the credentials of another user in github.com/ubuntu/authd
OSV
PAM module may allow accessing with the credentials of another user
osv·2024-10-03
CVE-2024-9313 [HIGH] PAM module may allow accessing with the credentials of another user
PAM module may allow accessing with the credentials of another user
Authd PAM module up to version 0.3.4 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.
This is possible using tools such as `su`, `sudo` or `ssh` (and potentially others) that, so far, do not ensure that the PAM user at the end of the transaction is matching the one who initiated the transaction.
Authd 0.3.5 fixes this by not allowing changing the user unless it was never set before in the PAM stack.
`su` version that will include https://github.com/util-linux/util-linux/pull/3206 will not be affected
`ssh` version that will include https://github.com/openssh/openssh-portable/pull/521 will not be affected
`sud
GHSA
PAM module may allow accessing with the credentials of another user
ghsa·2024-10-03
CVE-2024-9313 [HIGH] CWE-287 PAM module may allow accessing with the credentials of another user
PAM module may allow accessing with the credentials of another user
Authd PAM module up to version 0.3.4 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.
This is possible using tools such as `su`, `sudo` or `ssh` (and potentially others) that, so far, do not ensure that the PAM user at the end of the transaction is matching the one who initiated the transaction.
Authd 0.3.5 fixes this by not allowing changing the user unless it was never set before in the PAM stack.
`su` version that will include https://github.com/util-linux/util-linux/pull/3206 will not be affected
`ssh` version that will include https://github.com/openssh/openssh-portable/pull/521 will not be affected
`sud
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-03
Published