CVE-2024-56433
CVSS 3.1 Score 3.6 of 10 (low)
Details
Published Dec 26, 2024
CWE ID 1188
Summary
CVE-2024-56433 affects shadow-utils (shadow) versions 4.4 to 4.17.0, where a default behavior in the /etc/subuid file sets user IDs (uids) that can overlap with locally administered networks. This conflict may result in account takeover, as users with conflicting uids can gain access to NFS home directories or local resources via newuidmap. System administrators are advised against assigning uids within local networks that fall within the range of possible uids in /etc/subuid.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- OpenWrt