« Back to list

CVE-2024-9312

Status: AnalyzedMedium (6.4)—

Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-9312",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-9312",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-10T14:53:16.310907Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 0.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "repo": "https://github.com/ubuntu/authd",
          "vendor": "Canonical Ltd.",
          "product": "Authd",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.3.6",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "packageName": "authd"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:ubuntu:authd:*:*:*:*:*:*:*:*"
          ],
          "vendor": "ubuntu",
          "product": "authd",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.3.6",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-10-10T14:15:05.863",
  "references": [
    {
      "url": "https://github.com/ubuntu/authd/security/advisories/GHSA-4gfw-wf7c-w6g2",
      "tags": [
        "Exploit",
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-9312",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@ubuntu.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-286"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-335"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges."
    },
    {
      "lang": "es",
      "value": "Authd, hasta la versión 0.3.6, no aleatorizaba lo suficiente los identificadores de usuario para evitar colisiones. Un atacante local que pudiera registrar nombres de usuario podría falsificar el identificador de otro usuario y obtener sus privilegios."
    }
  ],
  "lastModified": "2026-06-17T08:24:20.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:canonical:authd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2665677-2BEF-4230-AF87-5C0530CF7193",
              "versionEndExcluding": "0.3.6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}