Skip to main content

Vendor/product archive

canonical / authd CVEs

Beta · best-effort

3 CVEs tagged to canonical / authd0 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2025-5689

Published Jun 16, 2025

A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9312

Published Oct 10, 2024

Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9313

Published Oct 3, 2024

Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including auth…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1