Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-3758

Опубликовано: 18 апр. 2024
Источник: debian

Описание

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sssdfixed2.9.5-1package
sssdfixed2.8.2-4+deb12u1bookwormpackage
sssdpostponedbusterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2223762

  • https://github.com/SSSD/sssd/pull/7302

  • https://github.com/SSSD/sssd/commit/d7db7971682da2dbf7642ac94940d6b0577ec35a (master)

  • https://github.com/SSSD/sssd/commit/e1bfbc2493c4194988acc3b2413df3dde0735ae3 (sssd-2-9 branch)

  • https://github.com/SSSD/sssd/commit/f4ebe1408e0bc67abfbfb5f0ca2ea13803b36726 (sssd-2-8-branch)

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 1 года назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

CVSS3: 7.1
redhat
больше 1 года назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

CVSS3: 7.1
nvd
больше 1 года назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

suse-cvrf
около 1 года назад

Security update for sssd

suse-cvrf
больше 1 года назад

Security update for sssd