CVE Vulnerabilities

CVE-2012-3462

Improper Authentication

Published: Dec 26, 2019 | Modified: Jan 03, 2020
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

A flaw was found in SSSD version 1.9.0. The SSSDs access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the users SELinux user context.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Sssd Fedoraproject 1.9.0 (including) 1.9.0 (including)
Sssd Ubuntu trusty *
Sssd Ubuntu upstream *

Potential Mitigations

References