CVE Database
/

CVE-2018-10852

Back to search

CVE-2018-10852

Published: Jun 26, 2018

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

3.8

LOW

Description

The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. This affects versions of SSSD before 1.16.3.

VendorProductVersions

[UNKNOWN]

sssd

affected
SSSD 1.16.3

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

Low

Integrity

None

Availability

None

References

RHSA-2018:3158
vendor-advisory
x_refsource_REDHAT
104547
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now