Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-3758

Опубликовано: 18 апр. 2024
Источник: debian
EPSS Низкий

Описание

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sssdfixed2.9.5-1package
sssdfixed2.8.2-4+deb12u1bookwormpackage
sssdpostponedbusterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2223762

  • https://github.com/SSSD/sssd/pull/7302

  • https://github.com/SSSD/sssd/commit/d7db7971682da2dbf7642ac94940d6b0577ec35a (master)

  • https://github.com/SSSD/sssd/commit/e1bfbc2493c4194988acc3b2413df3dde0735ae3 (sssd-2-9 branch)

  • https://github.com/SSSD/sssd/commit/f4ebe1408e0bc67abfbfb5f0ca2ea13803b36726 (sssd-2-8-branch)

EPSS

Процентиль: 4%
0.00022
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 1 года назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

CVSS3: 7.1
redhat
около 1 года назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

CVSS3: 7.1
nvd
около 1 года назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

suse-cvrf
около 1 года назад

Security update for sssd

suse-cvrf
около 1 года назад

Security update for sssd

EPSS

Процентиль: 4%
0.00022
Низкий