A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.
References
Information
Published : 2019-03-25 11:29
Updated : 2023-02-12 20:51
NVD link : CVE-2018-16838
Mitre link : CVE-2018-16838
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
redhat
- enterprise_linux
fedoraproject
- sssd