Skip to main content

Improper Privilege Management

CVE-2025-5689

Severity High
Score 8.5/10

Summary

A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session. This issue affects github.com/ubuntu/authd versions prior to 0.5.4.

  • LOW
  • NETWORK
  • LOW
  • CHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-269 - Improper Privilege Management

An effective privilege management infrastructure provides valid users with required access and privileges across heterogeneous technology environments. An application with a faulty privilege management infrastructure allows higher than authorized privileges or enables privilege escalation. This can lead to security incidents such as system infiltration, data breach, and complete system takeover.

References

Advisory Timeline

  • Published