Lucene search

K
redhatcveRedhat.comRH:CVE-2018-10852
HistoryJun 26, 2018 - 3:18 a.m.

CVE-2018-10852

2018-06-2603:18:41
redhat.com
access.redhat.com
16

EPSS

0.003

Percentile

66.4%

The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD utilizes too broad of a set of permissions. Any user who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user.