Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 20

Количество 20

suse-cvrf логотип

openSUSE-SU-2026:21290-1

21 день назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3195-1

9 дней назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3139-1

11 дней назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3131-1

11 дней назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3041-1

16 дней назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3025-1

16 дней назад

Security update for sssd

EPSS: Низкий
rocky логотип

RLSA-2026:42122

9 дней назад

Important: sssd security update

EPSS: Низкий
rocky логотип

RLSA-2026:41937

9 дней назад

Important: sssd security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-42122

9 дней назад

ELSA-2026-42122: sssd security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-41937

11 дней назад

ELSA-2026-41937: sssd security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-14476

24 дня назад

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2026-14476

24 дня назад

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2026-14476

24 дня назад

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2026-14476

24 дня назад

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_ ...

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2026-14474

24 дня назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-14474

24 дня назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-14474

24 дня назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-14474

24 дня назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_sear ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-v6qh-pm8g-3c5w

24 дня назад

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2vq9-j58h-2qj3

24 дня назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
openSUSE-SU-2026:21290-1

Security update for sssd

21 день назад
suse-cvrf логотип
SUSE-SU-2026:3195-1

Security update for sssd

9 дней назад
suse-cvrf логотип
SUSE-SU-2026:3139-1

Security update for sssd

11 дней назад
suse-cvrf логотип
SUSE-SU-2026:3131-1

Security update for sssd

11 дней назад
suse-cvrf логотип
SUSE-SU-2026:3041-1

Security update for sssd

16 дней назад
suse-cvrf логотип
SUSE-SU-2026:3025-1

Security update for sssd

16 дней назад
rocky логотип
RLSA-2026:42122

Important: sssd security update

9 дней назад
rocky логотип
RLSA-2026:41937

Important: sssd security update

9 дней назад
oracle-oval логотип
ELSA-2026-42122

ELSA-2026-42122: sssd security update (IMPORTANT)

9 дней назад
oracle-oval логотип
ELSA-2026-41937

ELSA-2026-41937: sssd security update (IMPORTANT)

11 дней назад
ubuntu логотип
CVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
1%
Низкий
24 дня назад
redhat логотип
CVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
1%
Низкий
24 дня назад
nvd логотип
CVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
1%
Низкий
24 дня назад
debian логотип
CVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_ ...

CVSS3: 8
1%
Низкий
24 дня назад
ubuntu логотип
CVE-2026-14474

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
0%
Низкий
24 дня назад
redhat логотип
CVE-2026-14474

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
0%
Низкий
24 дня назад
nvd логотип
CVE-2026-14474

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
0%
Низкий
24 дня назад
debian логотип
CVE-2026-14474

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_sear ...

CVSS3: 8.8
0%
Низкий
24 дня назад
github логотип
GHSA-v6qh-pm8g-3c5w

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

CVSS3: 8
1%
Низкий
24 дня назад
github логотип
GHSA-2vq9-j58h-2qj3

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
0%
Низкий
24 дня назад

Уязвимостей на страницу