Back to search
CVE-2013-0287
Published: Mar 21, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
openSUSE-SU-2013:0559
vendor-advisory
x_refsource_SUSE
52704
third-party-advisory
x_refsource_SECUNIA
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=910938
x_refsource_MISC
[sssd-devel] 20130319 [SSSD] A security bug in SSSD 1.9 (CVE-2013-0287)
mailing-list
x_refsource_MLIST
58593
vdb-entry
x_refsource_BID
52722
third-party-advisory
x_refsource_SECUNIA
1028317
vdb-entry
x_refsource_SECTRACK
RHSA-2013:0663
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now