Security restrictions bypass in System Security Services Daemon (SSSD) - CVE-2018-16838
Published: February 5, 2019 / Updated: May 9, 2023
Vulnerability details
The vulnerability allows a remote authenticated attacker to bypass security restrictions on the system.
The vulnerability exists due to a flaw in sssd Group Policy Objects implementation when the GPO is not readable by SSSD due to a too strict permission settings on the server side. A remote attacker can bypass security restrictions.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
sssd (Ubuntu package)
Data Computing Appliance (DCA)
How to mitigate CVE-2018-16838
Data Computing Appliance (DCA) - update to 4.3.0.0