CVE-2022-4254

sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
LDAP Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
Affected Products (NVD)
VendorProductVersion
fedoraprojectsssd
1.15.3 ≤
𝑥
< 2.3.1
redhatenterprise_linux
8.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_for_ibm_z_systems
7.0
redhatenterprise_linux_for_power_big_endian
7.0
redhatenterprise_linux_for_power_little_endian
7.0
redhatenterprise_linux_for_scientific_computing
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
8.2
redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
8.1
redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
8.2
redhatenterprise_linux_server_tus
8.2
redhatenterprise_linux_server_update_services_for_sap_solutions
8.1
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sssd
bookworm
2.8.2-4
fixed
bullseye
2.4.1-2
fixed
sid
2.9.5-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sssd
bionic
needed
focal
Fixed 2.2.3-3ubuntu0.11
released
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
ignored
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libipa_hbac-devel
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
libipa_hbac0
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
libsss_certmap-devel
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
libsss_certmap0
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
libsss_idmap-devel
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
libsss_idmap0
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
libsss_nss_idmap-devel
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
libsss_nss_idmap0
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
libsss_simpleifp-devel
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
libsss_simpleifp0
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
python-sssd-config
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
python3-sssd-config
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-32bit
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
sssd-ad
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-common
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-common-32bit
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-dbus
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-ipa
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-krb5
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-krb5-common
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-ldap
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-proxy
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-tools
suse enterprise sap 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 12 SP4
1.16.1-4.43.1
fixed
suse enterprise server 12 SP5
1.16.1-7.49.1
fixed
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
sssd-wbclient
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
sssd-wbclient-devel
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
sssd-winbind-idmap
suse enterprise server 15 SP1
1.16.1-150000.8.70.1
fixed
suse enterprise server 15 SP2
1.16.1-150200.17.26.1
fixed
suse enterprise server 15 SP3
1.16.1-150300.23.37.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libipa
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
libsss
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
python-libipa
RHEL 7
0:1.16.5-10.el7_9.15
fixed
python-libsss
RHEL 7
0:1.16.5-10.el7_9.15
fixed
python-sss
RHEL 7
0:1.16.5-10.el7_9.15
fixed
python-sss-murmur
RHEL 7
0:1.16.5-10.el7_9.15
fixed
python-sssdconfig
RHEL 7
0:1.16.5-10.el7_9.15
fixed
python3-libipa
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
python3-libsss
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
python3-sss
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
python3-sss-murmur
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
python3-sssdconfig
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-ad
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-client
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-common
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-common-pac
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-dbus
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-ipa
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-kcm
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-krb5
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-krb5-common
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-ldap
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-libwbclient
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-libwbclient-devel
RHEL 7
0:1.16.5-10.el7_9.15
fixed
sssd-nfs-idmap
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-polkit-rules
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-proxy
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-tools
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed
sssd-winbind-idmap
RHEL 7
0:1.16.5-10.el7_9.15
fixed
RHEL 8.1 E4S
0:2.2.0-19.el8_1.3
fixed
RHEL 8.2 AUS
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 E4S
0:2.2.3-20.el8_2.2
fixed
RHEL 8.2 TUS
0:2.2.3-20.el8_2.2
fixed