Количество 10
Количество 10
CVE-2017-12173
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.
CVE-2017-12173
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.
CVE-2017-12173
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.
CVE-2017-12173
It was found that sssd's sysdb_search_user_by_upn_res() function befor ...
openSUSE-SU-2017:2942-1
Security update for sssd
SUSE-SU-2017:2937-1
Security update for sssd
GHSA-w83x-jcpq-6cr7
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.
ELSA-2018-1877
ELSA-2018-1877: sssd and ding-libs security and bug fix update (MODERATE)
ELSA-2017-3379
ELSA-2017-3379: sssd security and bug fix update (MODERATE)
BDU:2019-04067
Уязвимость функции ssedb_search_user_by_upn_res() сервиса управления доступом к удаленным каталогам и механизмам аутентификации sssd, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-12173 It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it. | CVSS3: 4.3 | 0% Низкий | больше 7 лет назад | |
CVE-2017-12173 It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it. | CVSS3: 4.3 | 0% Низкий | около 8 лет назад | |
CVE-2017-12173 It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it. | CVSS3: 4.3 | 0% Низкий | больше 7 лет назад | |
CVE-2017-12173 It was found that sssd's sysdb_search_user_by_upn_res() function befor ... | CVSS3: 4.3 | 0% Низкий | больше 7 лет назад | |
openSUSE-SU-2017:2942-1 Security update for sssd | 0% Низкий | около 8 лет назад | ||
SUSE-SU-2017:2937-1 Security update for sssd | 0% Низкий | около 8 лет назад | ||
GHSA-w83x-jcpq-6cr7 It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
ELSA-2018-1877 ELSA-2018-1877: sssd and ding-libs security and bug fix update (MODERATE) | больше 7 лет назад | |||
ELSA-2017-3379 ELSA-2017-3379: sssd security and bug fix update (MODERATE) | почти 8 лет назад | |||
BDU:2019-04067 Уязвимость функции ssedb_search_user_by_upn_res() сервиса управления доступом к удаленным каталогам и механизмам аутентификации sssd, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 6.5 | 0% Низкий | больше 7 лет назад |
Уязвимостей на страницу