关键信息 CVE-2024-9312 CNA: Canonical Ltd. Published: 2024-10-10 Updated: 2024-10-10 Description Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges. CWE CWE-286: CWE-286 CVSS Score: 7.5 Severity: HIGH Version: 3.1 Vector String: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Product Status Vendor: Canonical Ltd. Product: Authd Platforms: Linux Versions Default Status: unknown Affected: affected from 0 before 0.3.6 Credits nicoo (finder) Michael Gebetsroither (analyst) Jamie Bliss (analyst) Adrian Dombeck (remediation developer) Mark Esler (coordinator) References GitHub CVE Record Authorized Data Publishers CISA-ADP