Skip to content
Discussion options

You must be logged in to vote

Hi, thanks for reaching out, but if you suspect that you have found a security vulnerability, please report it privately as documented in https://github.com/ubuntu/authd/blob/main/SECURITY.md#private-vulnerability-reporting. Fortunately, I don't think what you describe is a security vulnerability.

it turns out that any employee of the company who is in this group can log in to a colleague's device and again be in the sudo group, respectively, he can gain access to other people's data.

Yes, if you add a user to the linux-sudo group, they will have sudo access on all machines which they are allowed to log into via authd. That's the intended behavior.

Note that with the next release, it wi…

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by ArakelYorghanjyan
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants