sssd: simple access provider flaw prevents intended ACL use when client to an AD provider
Published Mar 21, 2013
4.9
MEDIUMCVSS 2.0
EPSS 2.15%
Description
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
Affected products
No data.
- 1.9.0
- 1.9.1
- 1.9.2
- 1.9.3
- 1.9.4
No data.
Red Hat Enterprise Linux 6
sssd-0:1.9.2-82.4.el6_4
Fixed · RHSA-2013:0663
Red Hat Enterprise Linux 5
sssd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | sssd-0:1.9.2-82.4.el6_4 | Fixed | RHSA-2013:0663 |
| Red Hat Enterprise Linux 5 | sssd | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:S/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 2.15% (0.02154) | 81.52th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.15% (0.02154) | 79.72th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.49% (0.00491) | 63.53th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.21% (0.00208) | 59.73th | v3 (v2023.03.01) |
| Feb 9, 2024 | 0.21% (0.00208) | 57.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.21% (0.00214) | 57.61th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.19% (0.02186) | 80.97th | v2 (v2022.01.01) |
| Feb 13, 2023 | 2.19% (0.02186) | 80.49th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.53% (0.02528) | 81.34th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.19% (0.02186) | 79.16th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.19% (0.02186) | 57.93th | v2 (v2022.01.01) |
References (20)
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=910938 x_refsource_MISC
- http://git.fedorahosted.org/cgit/sssd.git/patch/?id=26590d31f492dbbd36be6d0bde46a4bd3b221edb x_refsource_CONFIRMPatch
- http://git.fedorahosted.org/cgit/sssd.git/patch/?id=6569d57e3bc168e6e83d70333b48c5cb43aa04c4 x_refsource_CONFIRMPatch
- http://git.fedorahosted.org/cgit/sssd.git/patch/?id=6837eee3f7f81c0ee454d3718d67d7f3cc6b48ef x_refsource_CONFIRMPatch
- http://git.fedorahosted.org/cgit/sssd.git/patch/?id=754b09b5444e6da88ed58d6deaed8b815e268b6b x_refsource_CONFIRMPatch
- http://git.fedorahosted.org/cgit/sssd.git/patch/?id=7619be9f6bf649665fcbeee9e6b120f9f9cba2a5 x_refsource_CONFIRMPatch
- http://git.fedorahosted.org/cgit/sssd.git/patch/?id=8b8019fe3dd1564fba657e219ec20ff816c7ffdb x_refsource_CONFIRMPatch
- http://git.fedorahosted.org/cgit/sssd.git/patch/?id=b63830b142053f99bfe954d4be5a2b0f68ce3a93 x_refsource_CONFIRMPatch
- http://git.fedorahosted.org/cgit/sssd.git/patch/?id=c0bca1722d6f9dfb654ad78397be70f79ff39af1 x_refsource_CONFIRMPatch
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00115.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2013-0663.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/52704 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/52722 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1028317 vdb-entryx_refsource_SECTRACK
- http://www.securityfocus.com/bid/58593 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-0287 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=910938 Issue Tracking
- https://lists.fedorahosted.org/pipermail/sssd-devel/2013-March/014066.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2013-0287
- https://www.cve.org/CVERecord?id=CVE-2013-0287
Change history (0)
No recorded changes yet.