CVE-2022-4254
published 2023-02-01CVE-2022-4254: sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
PriorityP343high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.95%
57.4th percentile
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sssd | < sssd 2.3.1-1 (bookworm) | sssd 2.3.1-1 (bookworm) |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | >= 0 < 2.3.1-1 | 2.3.1-1 |
| fedoraproject | sssd | >= 0 < 2.3.1-1 | 2.3.1-1 |
| fedoraproject | sssd | >= 0 < 2.3.1-1 | 2.3.1-1 |
| fedoraproject | sssd | >= 0 < 2.3.1-1 | 2.3.1-1 |
| fedoraproject | sssd | >= 1.15.3 < 2.3.1 | 2.3.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_power_big_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_scientific_computing | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-4254: sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
osv·2023-02-01·CVSS 8.8
CVE-2022-4254 [HIGH] CVE-2022-4254: sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
GHSA
GHSA-x75f-4m4h-6374: sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
ghsa_unreviewed·2023-02-01
CVE-2022-4254 [HIGH] CWE-90 GHSA-x75f-4m4h-6374: sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
Ubuntu
SSSD vulnerability
vendor_ubuntu·2023-06-12
CVE-2022-4254 SSSD vulnerability
Title: SSSD vulnerability
Summary: SSSD could allow unintended access to network services.
It was discovered that SSSD incorrrectly sanitized certificate data used in
LDAP filters. When using this issue in combination with FreeIPA, a remote
attacker could possibly use this issue to escalate privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
vendor_redhat·2023-01-24·CVSS 8.8
CVE-2022-4254 [HIGH] CWE-90 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
A vulnerability was found in SSSD, in the libsss_certmap functionality. PKINIT enables a client to authenticate to the KDC using an X.509 certificate and the corresponding private key, rather than a passphrase or keytab. FreeIPA uses mapping rules to map a certificate presented during a PKINIT authentication request to the corresponding principal. The mapping filter is vulnerable to LDAP filter injection. The search result can be influenced by values in the certificate, which may be attacker controlled. In the most extreme case, an attacker could gain control of the admin account, leading to full domain takeover.
Statement: The issue w
Debian
CVE-2022-4254: sssd - sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
vendor_debian·2022·CVSS 8.8
CVE-2022-4254 [HIGH] CVE-2022-4254: sssd - sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
Scope: local
bookworm: resolved (fixed in 2.3.1-1)
bullseye: resolved (fixed in 2.3.1-1)
forky: resolved (fixed in 2.3.1-1)
sid: resolved (fixed in 2.3.1-1)
trixie: resolved (fixed in 2.3.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-4254https://bugzilla.redhat.com/show_bug.cgi?id=2149894https://github.com/SSSD/sssd/commit/a2b9a84460429181f2a4fa7e2bb5ab49fd561274https://github.com/SSSD/sssd/issues/5135https://lists.debian.org/debian-lts-announce/2023/05/msg00028.htmlhttps://access.redhat.com/security/cve/CVE-2022-4254https://bugzilla.redhat.com/show_bug.cgi?id=2149894https://github.com/SSSD/sssd/commit/a2b9a84460429181f2a4fa7e2bb5ab49fd561274https://github.com/SSSD/sssd/issues/5135https://lists.debian.org/debian-lts-announce/2023/05/msg00028.html
2023-02-01
Published