First published: Wed Dec 19 2018(Updated: )
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject Sssd | >=1.13.0<2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-16883.
The severity of CVE-2018-16883 is medium with a severity value of 5.5.
sssd versions from 1.13.0 to before 2.0.0 are affected by CVE-2018-16883.
If sensitive information were stored in the user directory, it could be inadvertently disclosed to local attackers.
To fix CVE-2018-16883, update sssd to version 2.0.0 or later.