Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16838

Опубликовано: 04 фев. 2019
Источник: redhat
CVSS3: 5.4

Описание

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sssdNot affected
Red Hat Enterprise Linux 6sssdNot affected
Red Hat Enterprise Linux 7sssdFixedRHSA-2019:217706.08.2019
Red Hat Enterprise Linux 8sssdFixedRHSA-2019:365105.11.2019
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7imgbasedFixedRHSA-2019:243712.08.2019
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7ovirt-node-ngFixedRHSA-2019:243712.08.2019
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-release-virtualization-hostFixedRHSA-2019:243712.08.2019
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-virtualization-hostFixedRHSA-2019:243712.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=1640820sssd: improper implementation of GPOs due to too restrictive permissions

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 7 лет назад

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.

CVSS3: 5.4
nvd
почти 7 лет назад

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.

CVSS3: 5.4
debian
почти 7 лет назад

A flaw was found in sssd Group Policy Objects implementation. When the ...

suse-cvrf
больше 6 лет назад

Security update for sssd

suse-cvrf
больше 6 лет назад

Security update for sssd

5.4 Medium

CVSS3