Red Hat sssd是美国Red Hat公司的一款数据库系统软件。 Red Hat sssd存在路径遍历漏洞,该漏洞源于SSSD的AD GPO提供程序中ad_gpo_extract_smb_components()函数未对gPCFileSysPath LDAP属性中的..序列进行清理,可能导致具有AD GPO管理权限的攻击者以root权限在GPO缓存目录之外写入文件,并通过注入Kerberos配置绕过身份验证。以下版本受到影响:Red Hat Enterprise Linux 10、Red Hat E
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:2.12.0-3.el10_2.1 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:2.10.2-3.el10_0.5 ~ * |
cpe:/o:redhat:enterprise_linux_eus:10.0
|
|
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:1.16.5-10.el7_9.18 ~ * |
cpe:/o:redhat:rhel_els:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.9.4-5.el8_10.5 ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.9.4-5.el8_10.5 ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:2.4.0-9.el8_4.5 ~ * |
cpe:/o:redhat:rhel_aus:8.4::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:2.4.0-9.el8_4.5 ~ * |
cpe:/o:redhat:rhel_aus:8.4::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:2.6.2-4.el8_6.5 ~ * |
cpe:/o:redhat:rhel_aus:8.6::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:2.6.2-4.el8_6.5 ~ * |
cpe:/o:redhat:rhel_aus:8.6::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:2.8.2-4.el8_8.4 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:2.8.2-4.el8_8.4 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.9.8-4.el9_8.1 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.9.8-4.el9_8.1 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:2.8.2-5.el9_2.7 ~ * |
cpe:/a:redhat:rhel_e4s:9.2::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:2.9.4-6.el9_4.5 ~ * |
cpe:/a:redhat:rhel_e4s:9.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:2.9.6-4.el9_6.5 ~ * |
cpe:/a:redhat:rhel_eus:9.6::appstream
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 412.86.202608241157-0 ~ * |
cpe:/a:redhat:openshift:4.12::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 413.92.202608111330-0 ~ * |
cpe:/a:redhat:openshift:4.13::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 414.92.202608172040-0 ~ * |
cpe:/a:redhat:openshift:4.14::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 415.92.202608180329-0 ~ * |
cpe:/a:redhat:openshift:4.15::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 416.94.202608150307-0 ~ * |
cpe:/a:redhat:openshift:4.16::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 417.94.202608250221-0 ~ * |
cpe:/a:redhat:openshift:4.17::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 418.94.202608142238-0 ~ * |
cpe:/a:redhat:openshift:4.18::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 4.19.9.6.202608120446-0 ~ * |
cpe:/a:redhat:openshift:4.19::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 4.20.9.6.202608121719-0 ~ * |
cpe:/a:redhat:openshift:4.20::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 4.21.9.6.202608122143-0 ~ * |
cpe:/a:redhat:openshift:4.21::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 4.22.9.8.202608130832-0 ~ * |
cpe:/a:redhat:openshift:4.22::el9
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14474 | 8.8 HIGH | Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by defa |
| CVE-2026-58384 | 7.3 HIGH | Gimp: gimp: integer overflow in read_rle_channel() |
| CVE-2025-12799 | 6.5 MEDIUM | Jastow: jastow cross-site scripting attack due to unsanitized uri |
| CVE-2026-14940 | 5.3 MEDIUM | 389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued |
| CVE-2026-14969 | 4.4 MEDIUM | 389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encry |
| CVE-2026-14935 | 3.7 LOW | Gstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without a=fingerprint |
No comments yet