Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qf7-r2vx-jf49

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

EPSS

Процентиль: 32%
0.00382
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 2.5
ubuntu
больше 7 лет назад

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

CVSS3: 2.5
redhat
больше 7 лет назад

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

CVSS3: 2.5
nvd
больше 7 лет назад

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

CVSS3: 2.5
debian
больше 7 лет назад

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict ac ...

EPSS

Процентиль: 32%
0.00382
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200