Advisories for Golang/Github.com/Ubuntu/Authd package

2025

New authd users logging in via SSH are members of the root group

When an authd user logs in via SSH for the first time (meaning they do not yet exist in the authd user database) and successfully authenticates via the configured broker, the user is considered a member of the root group in the context of that SSH session. This situation may allow the user to read and write files that are accessible by the root group, to which they should not …

2024