Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-0287

Опубликовано: 21 мар. 2013
Источник: nvd
CVSS2: 4.9
EPSS Низкий

Описание

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:fedoraproject:sssd:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.9.3:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.9.4:*:*:*:*:*:*:*

EPSS

Процентиль: 63%
0.00464
Низкий

4.9 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 12 лет назад

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

redhat
больше 12 лет назад

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

debian
больше 12 лет назад

The Simple Access Provider in System Security Services Daemon (SSSD) 1 ...

github
больше 3 лет назад

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

oracle-oval
больше 12 лет назад

ELSA-2013-0663: sssd security and bug fix update (MODERATE)

EPSS

Процентиль: 63%
0.00464
Низкий

4.9 Medium

CVSS2

Дефекты

CWE-264