以下是该漏洞描述的中文翻译: SSSD 的 IdP 身份验证组件中发现一个缺陷。 在 函数中,系统使用 并基于已认证用户标识符的长度来比较 OIDC 主题标识符,执行的是前缀比较而非精确匹配。因此,如果攻击者的 IdP 标识符是目标用户标识符的严格前缀(即目标标识符以攻击者标识符开头且更长),攻击者即可冒充目标用户完成认证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87766 | 8.8 HIGH | Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbo |
| CVE-2026-18147 | 8.1 HIGH | Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execut |
| CVE-2026-87874 | 8.1 HIGH | Community.general: community.general: memcached cache plugin deserializes untrusted pickle |
| CVE-2026-87872 | 6.8 MEDIUM | Community.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hardc |
| CVE-2026-19729 | 4.9 MEDIUM | Keycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing |
| CVE-2026-87875 | 4.3 MEDIUM | Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-l |
| CVE-2026-87876 | 3.0 LOW | Cups: openprinting cups: remaining case-insensitive username matching in scheduler side pa |
No comments yet