PT-2023-1263 · Sssd+6 · Sssd+6

Tej Rathi

·

Published

2020-08-04

·

Updated

2023-06-16

·

CVE-2022-4254

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sssd versions (affected versions not specified)
Description The issue is related to the libsss certmap package of the sssd service, which is responsible for managing access to remote directories and authentication mechanisms. It is associated with the inability to clear certificate data when using LDAP filtering. This could allow a remote attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2499
ALT-PU-2020-3407
ALT-PU-2021-1251
BDU:2023-00526
CESA-2023_0403
CVE-2022-4254
DLA-3436-1
DLA-3436-2
RHSA-2023:0397
RHSA-2023:0403
RHSA-2023:0442
RHSA-2023_0403
SUSE-SU-2023:0200-1
SUSE-SU-2023:0204-1
SUSE-SU-2023:0292-1
SUSE-SU-2023:0300-1
SUSE-SU-2023:0301-1
SUSE-SU-2023_0200-1
SUSE-SU-2023_0204-1
SUSE-SU-2023_0292-1
SUSE-SU-2023_0300-1
SUSE-SU-2023_0301-1
USN-6156-1
USN-6156-2

Affected Products

Alt Linux
Centos
Linuxmint
Red Hat
Suse
Ubuntu
Sssd