Information disclosure in System Security Services Daemon (SSSD) - CVE-2018-16883
Published: December 19, 2018 / Updated: May 9, 2023
System Security Services Daemon (SSSD)
Detailed vulnerability description
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to improper restriction of access to the infopipe according to the "allowed_uids" configuration parameter if sensitive information were stored in the user directory. A local attacker can gain access to potentially sensitive information.