Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
SSSD 安全漏洞
Vulnerability Description
SSSD是一款用于管理对远程目录和身份验证机制访问的守护进程。 SSSD 1.13.0版本至2.0.0之前版本中存在安全漏洞,该漏洞源于程序没有依照‘allowed_uids’配置参数正确地限制对infopipe服务的访问权限。本地攻击者可利用该漏洞获取存储在用户目录中的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A