Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from the 'Garuda settings manager', an insecure procedure is performed that keeps the created user without an assigned password during some seconds. This could allow a potential attacker to exploit this vulnerability in order to authenticate without knowing the password.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2023-10-04T15:00:49.765Z

Updated: 2024-08-03T17:09:08.631Z

Reserved: 2021-09-09T13:16:36.422Z

Link: CVE-2021-3784

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-10-04T16:15:09.940

Modified: 2024-11-21T06:22:25.310

Link: CVE-2021-3784

cve-icon Redhat

No data.