Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12728
HistoryJan 15, 2019 - 9:21 a.m.

Information Disclosure

2019-01-1509:21:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.002 Low

EPSS

Percentile

53.4%

sssd is vulnerable to information disclosure attacks. The vulnerability exists as it was found that sssd’s sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.