Security restrictions bypass in System Security Services Daemon (SSSD) - CVE-2018-16838

 

Security restrictions bypass in System Security Services Daemon (SSSD) - CVE-2018-16838

Published: February 5, 2019 / Updated: May 9, 2023


Vulnerability identifier: #VU17376
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16838
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to bypass security restrictions on the system.

The vulnerability exists due to a flaw in sssd Group Policy Objects implementation when the GPO is not readable by SSSD due to a too strict permission settings on the server side. A remote attacker can bypass security restrictions.


Affected software

System Security Services Daemon (SSSD)
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
sssd (Ubuntu package)
Data Computing Appliance (DCA)

How to mitigate CVE-2018-16838

Install update from vendor's website.

sssd (Ubuntu package) - addressed in versions 1.16.1-1ubuntu1.8, 2.2.3-3ubuntu0.7, 2.4.0-1ubuntu6.1
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins