Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mrc-5phh-m9pc

Опубликовано: 24 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.

A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.

EPSS

Процентиль: 24%
0.00082
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.6
ubuntu
около 2 лет назад

A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.

CVSS3: 6.6
redhat
больше 6 лет назад

A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.

CVSS3: 6.6
nvd
около 2 лет назад

A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.

CVSS3: 6.6
debian
около 2 лет назад

A flaw was found in sudo in the handling of ipa_hostname, where ipa_ho ...

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость программы для системного администрирования sudo, связанная с неправильным управлением привилегиями, позволяющая нарушителю обойти существующие ограничения безопасности и сохранить свои привилегии после их отзыва

EPSS

Процентиль: 24%
0.00082
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-269