Back

MEDIUM

sssd: Information leak in infopipe due to an improper uid restriction

Published Dec 19, 2018

Description

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.

Affected products

Remediation

Red Hat statement

The information exposed by this vulnerability is typically not highly sensitive. By default, it is only those fields returned by getpwent() and getgrent().

Red Hat mitigation

This vulnerability is only exposed if the infopipe service is enabled (enabled by default in Red Hat Enterprise Linux 7, disabled by default in Red Hat Enterprise Linux 6), and `[ifp].allowed_uids` is relied upon to protect sensitive information in the user directory.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 19, 2018
Updated Aug 5, 2024
Reserved Sep 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 19, 2018