VYPR
Low severity2.5OSV Advisory· Published Dec 19, 2018· Updated Jun 17, 2026

CVE-2018-16883

CVE-2018-16883

Description

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • SSSD/SssdOSV2 versions
    sssd-1_13_0, sssd-1_13_1, sssd-1_13_90, …+ 1 more
    • (no CPE)range: sssd-1_13_0, sssd-1_13_1, sssd-1_13_90, …
    • (no CPE)range: >=1.13.0,<2.0.0
  • cpe:2.3:a:fedoraproject:sssd:*:*:*:*:*:*:*:*
    Range: >=1.13.0,<2.0.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.