VYPR

SSSD

by Red Hat

Source repositories

CVEs (7)

  • CVE-2026-14474HigJul 7, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting…

  • CVE-2012-3462HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.02

    A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.

  • CVE-2026-14476HigJul 7, 2026
    risk 0.45cvss 8.0epss 0.01

    A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root.…

  • CVE-2018-16838MedMar 25, 2019
    risk 0.35cvss 5.4epss 0.01

    A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.

  • CVE-2017-12173MedJul 27, 2018
    risk 0.28cvss 4.3epss 0.01

    It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated…

  • CVE-2023-3758HigApr 18, 2024
    risk 0.00cvss 7.1epss 0.01

    A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.

  • CVE-2013-0287Mar 21, 2013
    risk 0.00cvss epss 0.02

    The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.