Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from the 'Garuda settings manager', an insecure procedure is performed that keeps the created user without an assigned password during some seconds. This could allow a potential attacker to exploit this vulnerability in order to authenticate without knowing the password.
History

Tue, 17 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2023-10-04T15:00:49.765Z

Updated: 2025-06-17T15:03:18.630Z

Reserved: 2021-09-09T13:16:36.422Z

Link: CVE-2021-3784

cve-icon Vulnrichment

Updated: 2024-08-03T17:09:08.631Z

cve-icon NVD

Status : Modified

Published: 2023-10-04T16:15:09.940

Modified: 2024-11-21T06:22:25.310

Link: CVE-2021-3784

cve-icon Redhat

No data.