CVE-2013-0287
published 2013-03-21CVE-2013-0287: The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce…
PriorityP426medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
2.15%
80.2th percentile
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | >= 0 < 1.11.4-1ubuntu2 | 1.11.4-1ubuntu2 |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
osv4.9MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h53f-x74p-cc2v: The Simple Access Provider in System Security Services Daemon (SSSD) 1
ghsa_unreviewed·2022-05-05
CVE-2013-0287 [MEDIUM] GHSA-h53f-x74p-cc2v: The Simple Access Provider in System Security Services Daemon (SSSD) 1
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
OSV
CVE-2013-0287: The Simple Access Provider in System Security Services Daemon (SSSD) 1
osv·2013-03-21·CVSS 4.9
CVE-2013-0287 [MEDIUM] CVE-2013-0287: The Simple Access Provider in System Security Services Daemon (SSSD) 1
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
Red Hat
sssd: simple access provider flaw prevents intended ACL use when client to an AD provider
vendor_redhat·2013-03-19·CVSS 4.9
CVE-2013-0287 [MEDIUM] sssd: simple access provider flaw prevents intended ACL use when client to an AD provider
sssd: simple access provider flaw prevents intended ACL use when client to an AD provider
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
Package: sssd (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-0287: sssd - The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 throu...
vendor_debian·2013·CVSS 4.9
CVE-2013-0287 [MEDIUM] CVE-2013-0287: sssd - The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 throu...
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0287 sssd: simple access provider flaw prevents intended ACL use when client to an AD provider [fedora-18]
bugzilla·2013-03-20·CVSS 4.9
CVE-2013-0287 [MEDIUM] CVE-2013-0287 sssd: simple access provider flaw prevents intended ACL use when client to an AD provider [fedora-18]
CVE-2013-0287 sssd: simple access provider flaw prevents intended ACL use when client to an AD provider [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when a
Bugzilla
CVE-2013-0287 sssd: simple access provider flaw prevents intended ACL use when client to an AD provider
bugzilla·2013-02-13·CVSS 4.9
CVE-2013-0287 [MEDIUM] CVE-2013-0287 sssd: simple access provider flaw prevents intended ACL use when client to an AD provider
CVE-2013-0287 sssd: simple access provider flaw prevents intended ACL use when client to an AD provider
Kaushik Banerjee discovered that SSSD's "simple" access provider did not work as expected when SSSD is configured as an Active Directory client when using the new (as of version 1.9.0) Active Directory provider. During the PAM account phase, SSSD may not not know the group name of a group that the user is a member of, but only the Windows Security Identifier. Because the group name is not known, the simple_deny_groups option does not work at all, and will always permit access; if any groups are noted in simple_deny_groups, all groups are permitted access. In addition, if any groups are noted in simple_allow_groups, access is always denied to everyone.
By default, the configuration will
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=910938http://git.fedorahosted.org/cgit/sssd.git/patch/?id=26590d31f492dbbd36be6d0bde46a4bd3b221edbhttp://git.fedorahosted.org/cgit/sssd.git/patch/?id=6569d57e3bc168e6e83d70333b48c5cb43aa04c4http://git.fedorahosted.org/cgit/sssd.git/patch/?id=6837eee3f7f81c0ee454d3718d67d7f3cc6b48efhttp://git.fedorahosted.org/cgit/sssd.git/patch/?id=754b09b5444e6da88ed58d6deaed8b815e268b6bhttp://git.fedorahosted.org/cgit/sssd.git/patch/?id=7619be9f6bf649665fcbeee9e6b120f9f9cba2a5http://git.fedorahosted.org/cgit/sssd.git/patch/?id=8b8019fe3dd1564fba657e219ec20ff816c7ffdbhttp://git.fedorahosted.org/cgit/sssd.git/patch/?id=b63830b142053f99bfe954d4be5a2b0f68ce3a93http://git.fedorahosted.org/cgit/sssd.git/patch/?id=c0bca1722d6f9dfb654ad78397be70f79ff39af1http://lists.opensuse.org/opensuse-updates/2013-03/msg00115.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0663.htmlhttp://secunia.com/advisories/52704http://secunia.com/advisories/52722http://securitytracker.com/id?1028317http://www.securityfocus.com/bid/58593https://lists.fedorahosted.org/pipermail/sssd-devel/2013-March/014066.htmlhttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=910938http://git.fedorahosted.org/cgit/sssd.git/patch/?id=26590d31f492dbbd36be6d0bde46a4bd3b221edbhttp://git.fedorahosted.org/cgit/sssd.git/patch/?id=6569d57e3bc168e6e83d70333b48c5cb43aa04c4http://git.fedorahosted.org/cgit/sssd.git/patch/?id=6837eee3f7f81c0ee454d3718d67d7f3cc6b48efhttp://git.fedorahosted.org/cgit/sssd.git/patch/?id=754b09b5444e6da88ed58d6deaed8b815e268b6bhttp://git.fedorahosted.org/cgit/sssd.git/patch/?id=7619be9f6bf649665fcbeee9e6b120f9f9cba2a5http://git.fedorahosted.org/cgit/sssd.git/patch/?id=8b8019fe3dd1564fba657e219ec20ff816c7ffdbhttp://git.fedorahosted.org/cgit/sssd.git/patch/?id=b63830b142053f99bfe954d4be5a2b0f68ce3a93http://git.fedorahosted.org/cgit/sssd.git/patch/?id=c0bca1722d6f9dfb654ad78397be70f79ff39af1http://lists.opensuse.org/opensuse-updates/2013-03/msg00115.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0663.htmlhttp://secunia.com/advisories/52704http://secunia.com/advisories/52722http://securitytracker.com/id?1028317http://www.securityfocus.com/bid/58593https://lists.fedorahosted.org/pipermail/sssd-devel/2013-March/014066.html
2013-03-21
Published