CVE-2024-9313

HIGH

Authd PAM <0.3.5 - Privilege Escalation

Title source: llm

Description

Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.

Scores

CVSS v3 8.8
EPSS 0.0066
EPSS Percentile 70.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

Status published

Affected Products (2)

canonical/authd < 0.3.5
ubuntu/authd < 0.0.0-20240930103526-63e527496b01Go

Timeline

Published Oct 03, 2024
Tracked Since Feb 18, 2026