Description
Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from the 'Garuda settings manager', an insecure procedure is performed that keeps the created user without an assigned password during some seconds. This could allow a potential attacker to exploit this vulnerability in order to authenticate without knowing the password.
Published: 2023-10-04
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

This vulnerability is already fixed in the last version of Garuda Linux.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-27047 Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from the 'Garuda settings manager', an insecure procedure is performed that keeps the created user without an assigned password during some seconds. This could allow a potential attacker to exploit this vulnerability in order to authenticate without knowing the password.
History

Tue, 17 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Garudalinux Garuda Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-06-17T15:03:18.630Z

Reserved: 2021-09-09T13:16:36.422Z

Link: CVE-2021-3784

cve-icon Vulnrichment

Updated: 2024-08-03T17:09:08.631Z

cve-icon NVD

Status : Modified

Published: 2023-10-04T16:15:09.940

Modified: 2024-11-21T06:22:25.310

Link: CVE-2021-3784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses