Access Control Vulnerability in System Security Services Daemon Affects Multiple Versions
CVE-2013-0287

Currently unrated

Key Information:

Status
Vendor
CVE Published:
21 March 2013

What is CVE-2013-0287?

A flaw in the Simple Access Provider of System Security Services Daemon (SSSD) versions 1.9.0 through 1.9.4 allows remote authenticated users to circumvent intended access restrictions. This is due to improper enforcement of the simple_deny_groups setting when the Active Directory provider is utilized, which may expose sensitive resources to unauthorized access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.