#VU71473 LDAP injection in System Security Services Daemon (SSSD) - CVE-2022-4254
Published: January 24, 2023
System Security Services Daemon (SSSD)
SSSD
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper input validation in libsss_certmap functionality when validating data used in DLAP queries. A remote non-authenticated attacker can use a specially crafted certificate to bypass authentication process and gain control of the admin account, leading to full domain takeover.