Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 23

Количество 23

debian логотип

CVE-2026-14474

3 месяца назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_sear ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-v6qh-pm8g-3c5w

3 месяца назад

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2vq9-j58h-2qj3

3 месяца назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2026-14474

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_sear ...

CVSS3: 8.8
1%
Низкий
3 месяца назад
github логотип
GHSA-v6qh-pm8g-3c5w

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
1%
Низкий
3 месяца назад
github логотип
GHSA-2vq9-j58h-2qj3

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
1%
Низкий
3 месяца назад

Уязвимостей на страницу