CVE-2017-7488

Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
authconfig_projectauthconfig
6.2.8
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
authconfig
RHEL 7
0:6.2.8-30.el7
fixed
authconfig-gtk
RHEL 7
0:6.2.8-30.el7
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
authconfig
Amazon Linux 1
0:6.2.8-30.31.amzn1
fixed
authconfig-debuginfo
Amazon Linux 1
0:6.2.8-30.31.amzn1
fixed