Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-16883

Опубликовано: 19 дек. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.1
CVSS3: 2.5

Описание

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

РелизСтатусПримечание
bionic

ignored

end of standard support, was deferred
cosmic

ignored

end of life
devel

not-affected

2.8.1-1ubuntu1
disco

ignored

end of life
eoan

ignored

end of life
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [1.11.8-0ubuntu0.7]]
esm-infra-legacy/xenial

deferred

esm-infra/bionic

deferred

esm-infra/focal

not-affected

2.2.3-3ubuntu0.9
esm-infra/xenial

ignored

end of ESM support, was deferred

Показывать по

Ссылки на источники

EPSS

Процентиль: 32%
0.00382
Низкий

2.1 Low

CVSS2

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.5
redhat
больше 7 лет назад

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

CVSS3: 2.5
nvd
больше 7 лет назад

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

CVSS3: 2.5
debian
больше 7 лет назад

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict ac ...

CVSS3: 5.5
github
больше 4 лет назад

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

EPSS

Процентиль: 32%
0.00382
Низкий

2.1 Low

CVSS2

2.5 Low

CVSS3