Описание
Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
Меры по смягчению последствий
Fixed on upstream master branch with commit f56844d and for versions 2.4.x with commit 88e67c0.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | cups | Fix deferred | ||
| Red Hat Enterprise Linux 6 | cups | Fix deferred | ||
| Red Hat Enterprise Linux 7 | cups | Fix deferred | ||
| Red Hat Enterprise Linux 8 | cups | Fix deferred | ||
| Red Hat Enterprise Linux 9 | cups | Fix deferred | ||
| Red Hat Enterprise Linux 9 | rhel9/cups | Fix deferred | ||
| Red Hat Hardened Images | cups | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos/rhcos | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
3 Low
CVSS3
Связанные уязвимости
(Two case-insensitive comparisons on request-derived usernames outside ...)
Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
Two case-insensitive comparisons on request-derived usernames outside ...
EPSS
3 Low
CVSS3