cbcvebase.
CVE-2019-3811
published 2019-01-15

CVE-2019-3811: A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty…

PriorityP421medium5.2CVSS 3.1
AVAACLPRLUIRSUCNINAH
EPSS
0.70%
49.0th percentile
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiansssd< sssd 2.2.0-1 (bookworm)sssd 2.2.0-1 (bookworm)
fedoraprojectsssd< 2.12.1
fedoraprojectsssd>= 0 < 2.2.0-12.2.0-1
fedoraprojectsssd>= 0 < 2.2.0-12.2.0-1
fedoraprojectsssd>= 0 < 2.2.0-12.2.0-1
fedoraprojectsssd>= 0 < 2.2.0-12.2.0-1
fedoraprojectsssd>= 0 < 1.16.1-1ubuntu1.81.16.1-1ubuntu1.8
fedoraprojectsssd>= 0 < 2.2.3-3ubuntu0.72.2.3-3ubuntu0.7
opensuseleap
opensuseleap
redhatenterprise_linux
the_sssd_projectsssd

CVSS provenance

nvdv3.15.2MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
nvdv3.04.1MEDIUMCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
osv7.5HIGH
vendor_debian5.2MEDIUM
vendor_redhat5.2MEDIUM
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.