CVE-2018-16838: Medium severity fedora hosted sssd vulnerability
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2018-16838?
CVE-2018-16838 is a vulnerability in the sssd Group Policy Objects implementation that allows all authenticated users to login when the GPO is not readable due to strict permission settings on the server side.
How severe is CVE-2018-16838?
CVE-2018-16838 has a severity rating of 5.4, which is considered medium.
Which software is affected by CVE-2018-16838?
The affected software includes sssd versions 1.16.4-21.el7 and 2.2.0-19.el8, imgbased version 1.1.9-0.1.el7e, ovirt-node-ng version 4.3.5-0.20190717.0.el7e, redhat-release-virtualization-host version 4.3.5-2.el7e, redhat-virtualization-host version 4.3.5-20190722.0.el7_7, Fedora Sssd, and Redhat Enterprise Linux 7.0.
How do I fix CVE-2018-16838?
To fix CVE-2018-16838, update your sssd package to version 1.16.4-21.el7 or 2.2.0-19.el8, or apply the appropriate remedy provided by your software vendor.
Where can I find more information about CVE-2018-16838?
You can find more information about CVE-2018-16838 on the following references: [1] (link to https://pagure.io/SSSD/sssd/c/ad058011b6b75b15c674be46a3ae9b3cc5228175), [2] (link to https://pagure.io/SSSD/sssd/issue/3867), and [3] (link to https://access.redhat.com/errata/RHSA-2019:2177).