Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3758

Опубликовано: 16 апр. 2024
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

Отчет

This flaw is triggered by a race condition which makes it difficult to exploit. Also, it depends on non default GPO configuration on the server side. This two aspects lowers the severity of the issue to Moderate.

Меры по смягчению последствий

A mitigation can be applied to the sssd.conf file that would make the occurrence of the race condition more difficult:

  1. Increase the GPO cache time out editing the following configuration directive in sssd.conf file: a) ad_gpo_cache_timeout = 3600 Ps.: This value (3600) should make the cache time out in one hour but would make GPO updates propagation from AD server to local machines take longer. [1] https://access.redhat.com/documentation/pt-br/red_hat_enterprise_linux/7/html/windows_integration_guide/sssd-gpo

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sssdOut of support scope
Red Hat Enterprise Linux 7sssdOut of support scope
Red Hat Enterprise Linux 8sssdFixedRHSA-2024:327022.05.2024
Red Hat Enterprise Linux 8sssdFixedRHSA-2024:327022.05.2024
Red Hat Enterprise Linux 8.6 Extended Update SupportsssdFixedRHSA-2024:192118.04.2024
Red Hat Enterprise Linux 8.8 Extended Update SupportsssdFixedRHSA-2024:192218.04.2024
Red Hat Enterprise Linux 9sssdFixedRHSA-2024:257130.04.2024
Red Hat Enterprise Linux 9sssdFixedRHSA-2024:257130.04.2024
Red Hat Enterprise Linux 9.0 Extended Update SupportsssdFixedRHSA-2024:191918.04.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportsssdFixedRHSA-2024:192018.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=2223762sssd: Race condition during authorization leads to GPO policies functioning inconsistently

EPSS

Процентиль: 4%
0.00022
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 1 года назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

CVSS3: 7.1
nvd
около 1 года назад

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

CVSS3: 7.1
debian
около 1 года назад

A race condition flaw was found in sssd where the GPO policy is not co ...

suse-cvrf
около 1 года назад

Security update for sssd

suse-cvrf
около 1 года назад

Security update for sssd

EPSS

Процентиль: 4%
0.00022
Низкий

7.1 High

CVSS3