Back to search
CVE-2018-16838
Published: Mar 25, 2019
Modified: Feb 13, 2025
PUBLISHED
CVSS v3.0
5.4
MEDIUM
Description
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.
| Vendor | Product | Versions |
|---|---|---|
[UNKNOWN] | sssd | affected n/a |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16838
x_refsource_CONFIRM
openSUSE-SU-2019:1576
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1589
vendor-advisory
x_refsource_SUSE
RHSA-2019:2177
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2437
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3651
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now