CVE-2024-9312

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 10, 2024
Updated: Oct 15, 2024
CWE ID 286

Summary

CVE-2024-9312 is a vulnerability affecting Authd, specifically versions up to 0.3.6. This issue stems from a lack of sufficient randomization in user ID generation, resulting in the potential for collisions. Consequently, a local attacker with the ability to register user names may successfully impersonate another user, gaining unauthorized access to their privileges. This vulnerability poses a significant risk, particularly in multi-user environments where user authentication is critical. It is crucial for organizations using Authd to upgrade to a patched version as soon as possible to mitigate this exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share