CVE-2021-3621
published 2021-12-23CVE-2021-3621: A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows…
PriorityP356high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.52%
83.2th percentile
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sssd | < sssd 2.5.2-1 (bookworm) | sssd 2.5.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | >= 0 < 2.4.1-2+deb11u1 | 2.4.1-2+deb11u1 |
| fedoraproject | sssd | >= 0 < 2.5.2-1 | 2.5.2-1 |
| fedoraproject | sssd | >= 0 < 2.5.2-1 | 2.5.2-1 |
| fedoraproject | sssd | >= 0 < 2.5.2-1 | 2.5.2-1 |
| fedoraproject | sssd | >= 0 < 1.16.1-1ubuntu1.8 | 1.16.1-1ubuntu1.8 |
| fedoraproject | sssd | >= 0 < 2.2.3-3ubuntu0.7 | 2.2.3-3ubuntu0.7 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | virtualization | — | — |
| redhat | virtualization_host | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g527-g4q2-57xc: A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands
ghsa_unreviewed·2021-12-24
CVE-2021-3621 [HIGH] CWE-77 GHSA-g527-g4q2-57xc: A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
OSV
CVE-2021-3621: A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands
osv·2021-12-23·CVSS 8.8
CVE-2021-3621 [HIGH] CVE-2021-3621: A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
OSV
sssd vulnerabilities
osv·2021-09-08·CVSS 7.5
CVE-2018-10852 [HIGH] sssd vulnerabilities
sssd vulnerabilities
Jakub Hrozek discovered that SSSD incorrectly handled file permissions. A
local attacker could possibly use this issue to read the sudo rules
available for any user. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10852)
It was discovered that SSSD incorrectly handled Group Policy Objects. When
SSSD is configured with too strict permissions causing the GPO to not be
readable, SSSD will allow all authenticated users to login instead of being
denied, contrary to expectations. This issue only affected Ubuntu 18.04
LTS. (CVE-2018-16838)
It was discovered that SSSD incorrectly handled users with no home
directory set. When no home directory was set, SSSD would return the root
directory instead of an empty string, possibly bypassing security measures.
This issue only
Ubuntu
SSSD vulnerabilities
vendor_ubuntu·2021-09-08·CVSS 3.8
CVE-2021-3621 [LOW] SSSD vulnerabilities
Title: SSSD vulnerabilities
Summary: Several security issues were fixed in sssd.
Jakub Hrozek discovered that SSSD incorrectly handled file permissions. A
local attacker could possibly use this issue to read the sudo rules
available for any user. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10852)
It was discovered that SSSD incorrectly handled Group Policy Objects. When
SSSD is configured with too strict permissions causing the GPO to not be
readable, SSSD will allow all authenticated users to login instead of being
denied, contrary to expectations. This issue only affected Ubuntu 18.04
LTS. (CVE-2018-16838)
It was discovered that SSSD incorrectly handled users with no home
directory set. When no home directory was set, SSSD would return the root
directory instead of an empty
Red Hat
sssd: shell command injection in sssctl
vendor_redhat·2021-08-16·CVSS 8.8
CVE-2021-3621 [HIGH] CWE-78 sssd: shell command injection in sssctl
sssd: shell command injection in sssctl
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well
Debian
CVE-2021-3621: sssd - A flaw was found in SSSD, where the sssctl command was vulnerable to shell comma...
vendor_debian·2021·CVSS 8.8
CVE-2021-3621 [HIGH] CVE-2021-3621: sssd - A flaw was found in SSSD, where the sssctl command was vulnerable to shell comma...
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Scope: local
bookworm: resolved (fixed in 2.5.2-1)
bullseye: resolved (fixed in 2.4.1-2+deb11u1)
forky: resolved (fixed in 2.5.2-1)
sid: resolved (fixed in 2.5.2-1)
trixie: resolved (fixed in 2.5.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1975142https://lists.debian.org/debian-lts-announce/2023/05/msg00028.htmlhttps://sssd.io/release-notes/sssd-2.6.0.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1975142https://lists.debian.org/debian-lts-announce/2023/05/msg00028.htmlhttps://lists.debian.org/debian-lts-announce/2025/02/msg00008.htmlhttps://sssd.io/release-notes/sssd-2.6.0.html
2021-12-23
Published