A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.
2019-03-25T18:29:00.433
2024-11-21T03:53:24.937
Modified
CVSSv3.0: 5.4 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fedoraproject | sssd | - | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |