CVE-2013-0287

EUVD-2013-0308
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.9 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
Affected Products (NVD)
VendorProductVersion
fedoraprojectsssd
1.9.0
fedoraprojectsssd
1.9.1
fedoraprojectsssd
1.9.2
fedoraprojectsssd
1.9.3
fedoraprojectsssd
1.9.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sssd
bookworm
2.8.2-4
fixed
bullseye
2.4.1-2
fixed
sid
2.9.5-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sssd
hardy
dne
lucid
not-affected
oneiric
not-affected
precise
not-affected
quantal
ignored
raring
ignored
saucy
not-affected
trusty
dne
Common Weakness Enumeration
References