Skip to content

A user account with a password set is allowed to log in without the password #262

@LinuxOnTheDesktop

Description

@LinuxOnTheDesktop
  1. I have an existing user account called 'present'.
  2. I changed that user's password using the 'passwd' tool.
  3. Using a tty shows that the new password is set. (If and only if I enter that password can I login with 'present' at the tty.)
  4. The greeter does not require the password - it logs me as soon as I click on the username,

So far I can tell, the greeter is not set to login 'present' automatically:

Image

This problem seems to be a security vulnerability. But I see no option here for private reporting.

EDIT: I did, before opening this issue, discuss the problem on the Mint forum. But no light seemed to be shed there on the problem.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions