Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 23

Количество 23

suse-cvrf логотип

openSUSE-SU-2026:21290-1

2 месяца назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3195-1

2 месяца назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3139-1

2 месяца назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3131-1

2 месяца назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3041-1

2 месяца назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3025-1

2 месяца назад

Security update for sssd

EPSS: Низкий
rocky логотип

RLSA-2026:46990

около 2 месяцев назад

Important: sssd security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:42122

2 месяца назад

Important: sssd security update

EPSS: Низкий
rocky логотип

RLSA-2026:41937

2 месяца назад

Important: sssd security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-50109-0

около 1 месяца назад

ELSA-2026-50109-0: sssd security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-46990

около 2 месяцев назад

ELSA-2026-46990: sssd security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-42122

2 месяца назад

ELSA-2026-42122: sssd security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-41937

2 месяца назад

ELSA-2026-41937: sssd security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-14476

3 месяца назад

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2026-14476

3 месяца назад

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2026-14476

3 месяца назад

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2026-14476

3 месяца назад

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_ ...

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2026-14474

3 месяца назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-14474

3 месяца назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-14474

3 месяца назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
openSUSE-SU-2026:21290-1

Security update for sssd

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3195-1

Security update for sssd

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3139-1

Security update for sssd

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3131-1

Security update for sssd

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3041-1

Security update for sssd

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3025-1

Security update for sssd

2 месяца назад
rocky логотип
RLSA-2026:46990

Important: sssd security, bug fix, and enhancement update

около 2 месяцев назад
rocky логотип
RLSA-2026:42122

Important: sssd security update

2 месяца назад
rocky логотип
RLSA-2026:41937

Important: sssd security update

2 месяца назад
oracle-oval логотип
ELSA-2026-50109-0

ELSA-2026-50109-0: sssd security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-46990

ELSA-2026-46990: sssd security, bug fix, and enhancement update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-42122

ELSA-2026-42122: sssd security update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2026-41937

ELSA-2026-41937: sssd security update (IMPORTANT)

2 месяца назад
ubuntu логотип
CVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_ ...

CVSS3: 8
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-14474

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-14474

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-14474

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
1%
Низкий
3 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.