Skip to main content

Vendor/product archive

fedoraproject / sssd CVEs

Beta · best-effort

19 CVEs tagged to fedoraproject / sssd0 Critical, 4 High, 8 Medium, 7 Low, 0 Unrated.

CVE-2026-12610

Published Jun 30, 2026

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2021-3621

Published Dec 23, 2021

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick…

CVSS 8.8 · High

CVE-2012-3462

Published Dec 26, 2019

A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16883

Published Dec 19, 2018

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were s…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-5292

Published Oct 29, 2015

Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security Services Daemon (SSSD) 1.10 before 1.13.1 allows remote authentic…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0287

Published Mar 21, 2013

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_gro…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0220

Published Feb 24, 2013

The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1758

Published May 26, 2011

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentica…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-4341

Published Jan 25, 2011

The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite lo…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2940

Published Aug 30, 2010

The auth_send function in providers/ldap/ldap_auth.c in System Security Services Daemon (SSSD) 1.3.0, when LDAP authentication and anonymous bind are enabled, allows remote attack…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0014

Published Jan 14, 2010

System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, v…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1