VDB
BDU%3A2023-00526
BDU%3A2023-00526
PUBLISHED
CVSS 10 CRITICAL
Уязвимость пакета libsss_certmap сервиса управления доступом к удаленным каталогам и механизма аутентификации sssd, позволяющая нарушителю повысить свои привилегии
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., ООО «РусБИТех-Астра», Novell Inc., Сообщество свободного программного обеспечения | Red Hat Enterprise Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Server for SAP Applications, Debian GNU/Linux, SUSE OpenStack Cloud, Astra Linux Special Edition для «Эльбрус» (запись в едином реестре российских программ №11156), Suse Linux Enterprise Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise Micro, SUSE Manager Retail Branch Server, openSUSE Leap Micro, SUSE Enterprise Storage, sssd, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Real Time |
Timeline
- Feb 1, 2023 CVE Published
- Sep 13, 2024 CVE Updated
References
- https://github.com/SSSD/sssd/issues/5135 url
- https://github.com/SSSD/sssd/commit/a2b9a84460429181f2a4fa7e2bb5ab49fd561274 url
- https://security-tracker.debian.org/tracker/CVE-2022-4254 url
- https://www.suse.com/security/cve/CVE-2022-4254.html url
- https://access.redhat.com/security/cve/cve-2022-4254 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2149894 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20230525SE16MD url
- https://wiki.astralinux.ru/astra-linux-se81-bulletin-20230315SE81 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20231214SE16 url