Back

MEDIUM

authconfig: Information leak when SSSD is used for authentication against remote server

Published May 16, 2017

Description

Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames.

Affected products

Remediation

Red Hat mitigation

Possible workaround (with side-effects): authconfig --enablesysnetauth --update

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 16, 2017
Updated Aug 5, 2024
Reserved Apr 5, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 9, 2017