CVE-2024-9312
Status: AnalyzedMedium (6.4)—
Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- Base score: 6.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.28%
- Percentile among all scored CVEs: 19
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-286
- CWE-335
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-9312",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-9312",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-10-10T14:53:16.310907Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@ubuntu.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 0.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.5
}
]
},
"affected": [
{
"source": "security@ubuntu.com",
"affectedData": [
{
"repo": "https://github.com/ubuntu/authd",
"vendor": "Canonical Ltd.",
"product": "Authd",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "0.3.6",
"versionType": "semver"
}
],
"platforms": [
"Linux"
],
"packageName": "authd"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:ubuntu:authd:*:*:*:*:*:*:*:*"
],
"vendor": "ubuntu",
"product": "authd",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "0.3.6",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-10-10T14:15:05.863",
"references": [
{
"url": "https://github.com/ubuntu/authd/security/advisories/GHSA-4gfw-wf7c-w6g2",
"tags": [
"Exploit",
"Mitigation",
"Vendor Advisory"
],
"source": "security@ubuntu.com"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2024-9312",
"tags": [
"Third Party Advisory"
],
"source": "security@ubuntu.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@ubuntu.com",
"description": [
{
"lang": "en",
"value": "CWE-286"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-335"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges."
},
{
"lang": "es",
"value": "Authd, hasta la versión 0.3.6, no aleatorizaba lo suficiente los identificadores de usuario para evitar colisiones. Un atacante local que pudiera registrar nombres de usuario podría falsificar el identificador de otro usuario y obtener sus privilegios."
}
],
"lastModified": "2026-06-17T08:24:20.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:canonical:authd:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2665677-2BEF-4230-AF87-5C0530CF7193",
"versionEndExcluding": "0.3.6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@ubuntu.com"
}