Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18385 | A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session. |
Github GHSA |
GHSA-g8qw-mgjx-rwjr | New authd users logging in via SSH are members of the root group |
Tue, 26 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical authd |
|
| CPEs | cpe:2.3:a:canonical:authd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Canonical
Canonical authd |
Tue, 17 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 |
Tue, 17 Jun 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 17 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 16 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Jun 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session. | |
| Title | Improper Permission Management in SSH Session Handling | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2025-06-17T17:27:04.238Z
Reserved: 2025-06-04T17:12:16.505Z
Link: CVE-2025-5689
Updated: 2025-06-16T14:31:18.283Z
Status : Analyzed
Published: 2025-06-16T12:15:19.610
Modified: 2025-08-26T16:04:34.083
Link: CVE-2025-5689
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA