Lucene search

K
huntrYsfEA82CFC9-B55C-41FE-AE58-0D0E0BD7AB62
HistoryMar 06, 2022 - 10:34 a.m.

Improper Authorization

2022-03-0610:34:14
ysf
www.huntr.dev
8

0.002 Low

EPSS

Percentile

51.4%

Description

When Gogs is build and configured for PAM authentification it skips checking authorization completely. Therefore expired accounts and accounts with expired passwords can still login.

Proof of Concept

You can expire an account with chage -E0 <username> and still login.

Impact

Since disabling an account in PAM still allows to login via ssh-keys, it’s common to set accounts to expire if you want to deny access. So accounts whom have been privilege revoked are still able to login.

0.002 Low

EPSS

Percentile

51.4%

Related for EA82CFC9-B55C-41FE-AE58-0D0E0BD7AB62