Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:fedoraproject:sssd:1.16.4:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2022-4254 |
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters Published: February 01, 2023; 12:15:09 PM -0500 |
V3.1: 8.8 HIGH V2.0:(not available) |
CVE-2019-3811 |
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable. Published: January 15, 2019; 10:29:00 AM -0500 |
V3.1: 5.2 MEDIUM V2.0: 2.7 LOW |
CVE-2018-16883 |
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers. Published: December 19, 2018; 9:29:00 AM -0500 |
V3.0: 5.5 MEDIUM V2.0: 2.1 LOW |