Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-882h-52g4-fpjv

Опубликовано: 19 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

EPSS

Процентиль: 47%
0.00241
Низкий

7.2 High

CVSS3

Дефекты

CWE-287
CWE-362

Связанные уязвимости

CVSS3: 7.2
ubuntu
почти 4 года назад

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

CVSS3: 7.2
redhat
около 4 лет назад

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

CVSS3: 7.2
nvd
почти 4 года назад

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

CVSS3: 7.2
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.2
debian
почти 4 года назад

A flaw was found in the way Samba, as an Active Directory Domain Contr ...

EPSS

Процентиль: 47%
0.00241
Низкий

7.2 High

CVSS3

Дефекты

CWE-287
CWE-362