Vulnerabilities > Fedoraproject > Sssd

DATE CVE VULNERABILITY TITLE RISK
2023-02-01 CVE-2022-4254 LDAP Injection vulnerability in multiple products
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
network
low complexity
fedoraproject redhat CWE-90
8.8
2021-12-23 CVE-2021-3621 OS Command Injection vulnerability in multiple products
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands.
network
low complexity
fedoraproject redhat CWE-78
8.8
2019-12-26 CVE-2012-3462 Improper Authentication vulnerability in Fedoraproject Sssd 1.9.0
A flaw was found in SSSD version 1.9.0.
network
low complexity
fedoraproject CWE-287
6.5
2019-03-25 CVE-2018-16838 Improper Privilege Management vulnerability in multiple products
A flaw was found in sssd Group Policy Objects implementation.
network
low complexity
fedoraproject redhat CWE-269
5.4
2019-01-15 CVE-2019-3811 A vulnerability was found in sssd. 5.2
2018-12-19 CVE-2018-16883 Information Exposure vulnerability in Fedoraproject Sssd
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter.
local
low complexity
fedoraproject CWE-200
2.1
2018-07-27 CVE-2017-12173 Improper Input Validation vulnerability in multiple products
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection.
network
low complexity
redhat fedoraproject CWE-20
4.0
2018-06-26 CVE-2018-10852 Information Exposure vulnerability in multiple products
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user.
network
low complexity
debian fedoraproject redhat CWE-200
5.0
2014-06-11 CVE-2014-0249 Permissions, Privileges, and Access Controls vulnerability in multiple products
The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a non-POSIX group is in a group membership chain, which allows local users to bypass access restrictions via unspecified vectors.
3.3
2013-03-21 CVE-2013-0287 Permissions, Privileges, and Access Controls vulnerability in Fedoraproject Sssd
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
4.9