First published: Sat Dec 23 2023(Updated: )
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/sudo | <1.8.28 | 1.8.28 |
Sudo | <1.8.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7090 has a significant severity rating due to its impact on privilege mismanagement.
To resolve CVE-2023-7090, users should upgrade to sudo version 1.8.28 or later.
CVE-2023-7090 is caused by improper handling of the ipa_hostname in sudo, leading to privilege retention issues.
Users of sudo versions prior to 1.8.28 are vulnerable to CVE-2023-7090.
There are no documented workarounds for CVE-2023-7090; upgrading is the recommended solution.