CVE-2019-3811Sensitive Information Exposure in Sssd

Severity
5.2MEDIUMNVD
EPSS
0.1%
top 69.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15
Latest updateMay 13

Description

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:HExploitability: 1.5 | Impact: 3.6

Affected Packages4 packages

Debianfedoraproject/sssd< 2.2.0-1+3
CVEListV5the_sssd_project/sssd2.1
NVDopensuse/leap15.0, 42.3+1

Also affects: Debian Linux 8.0, Enterprise Linux 7.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x3cx-wjrx-m7rj: A vulnerability was found in sssd2022-05-13
OSV
CVE-2019-3811: A vulnerability was found in sssd2019-01-15
CVEList
CVE-2019-3811: A vulnerability was found in sssd2019-01-15

📋Vendor Advisories

3
Ubuntu
SSSD vulnerabilities2021-09-08
Debian
CVE-2019-3811: sssd - A vulnerability was found in sssd. If a user was configured with no home directo...2019
Red Hat
sssd: fallback_homedir returns '/' for empty home directories in passwd file2018-12-04

💬Community

2
Bugzilla
CVE-2019-3811 sssd: fallback_homedir returns '/' for empty home directories in passwd file2018-12-05
Bugzilla
CVE-2019-3811 sssd: fallback_homedir returns '/' for empty home directories in passwd file [fedora-all]2018-12-05
CVE-2019-3811 — Sensitive Information Exposure in Sssd | cvebase