sssd: unsanitized input when searching in local cache database
Published Jul 27, 2018
8.8
HIGHCVSS 3.0
EPSS 1.50%
Description
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.
Affected products
-
- Version 1.16.0StatusaffectedConstraints-
- Version
Configuration 1
- 6.0
- 7.0
- 6.0
- 7.0
- 7.4
- 7.4
- 7.5
- 6.0
- 7.0
Configuration 2
- < 1.16.0
No data.
Red Hat Enterprise Linux 6
ding-libs-0:0.4.0-13.el6
Fixed · RHSA-2018:1877
Red Hat Enterprise Linux 6
sssd-0:1.13.3-60.el6
Fixed · RHSA-2018:1877
Red Hat Enterprise Linux 7
sssd-0:1.15.2-50.el7_4.8
Fixed · RHSA-2017:3379
Red Hat Enterprise Linux 5
sssd
Not affected
Red Hat Satellite 6
sssd
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ding-libs-0:0.4.0-13.el6 | Fixed | RHSA-2018:1877 |
| Red Hat Enterprise Linux 6 | sssd-0:1.13.3-60.el6 | Fixed | RHSA-2018:1877 |
| Red Hat Enterprise Linux 7 | sssd-0:1.15.2-50.el7_4.8 | Fixed | RHSA-2017:3379 |
| Red Hat Enterprise Linux 5 | sssd | Not affected | n/a |
| Red Hat Satellite 6 | sssd | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of sssd as shipped with Red Hat Satellite version 6.0. More recent versions of Satellite no longer ships sssd. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Red Hat mitigation
It is possible to disable manually credential caching : * Stop the sssd service * Delete the cache (rm -f /var/lib/sss/db/* /var/log/sssd/*) or manually remove the hashes for the database * In the sssd configuration file, change cache_credentials to False for each domains * start the sssd service again However, tools such as realmd & ipa-client-install might enable credential caching, and should be used with care.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
AV:N/AC:L/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.50% (0.01499) | 73.31th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.50% (0.01499) | 73.10th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.17% (0.00166) | 53.64th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.17% (0.00166) | 52.61th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.17% (0.00173) | 52.55th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00890) | 30.33th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00890) | 12.04th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.83% (0.00833) | 24.58th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.83% (0.00833) | 0.00th | v1 |
References (7)
- https://access.redhat.com/errata/RHSA-2017:3379 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1877 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2017-12173 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1498173 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12173 x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-12173
- https://www.cve.org/CVERecord?id=CVE-2017-12173
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2017:3379 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2018:1877 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2017-12173 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1498173 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12173 | x_refsource_CONFIRMIssue TrackingPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-12173 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-12173 |
Change history (0)
No recorded changes yet.