CVE-2023-3758
published 2024-04-18CVE-2023-3758: A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization…
PriorityP433high7.1CVSS 3.1
AVAACHPRLUINSUCHIHAH
EPSS
1.03%
59.8th percentile
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sssd | < sssd 2.8.2-4+deb12u1 (bookworm) | sssd 2.8.2-4+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | sssd | < 2.9.5 | 2.9.5 |
| fedoraproject | sssd | >= 0 < 2.4.1-2+deb11u1 | 2.4.1-2+deb11u1 |
| fedoraproject | sssd | >= 0 < 2.8.2-4+deb12u1 | 2.8.2-4+deb12u1 |
| fedoraproject | sssd | >= 0 < 2.9.5-1 | 2.9.5-1 |
| fedoraproject | sssd | >= 0 < 2.9.5-1 | 2.9.5-1 |
| redhat | codeready_linux_builder | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_for_arm64 | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
SSSD vulnerability
vendor_ubuntu·2024-06-17
CVE-2023-3758 SSSD vulnerability
Title: SSSD vulnerability
Summary: SSSD did not always correctly apply the GPO policy.
It was discovered that SSSD did not always correctly apply the GPO policy
for authenticated users, contrary to expectations. This could result in
improper authorization or improper access to resources.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sssd: Race condition during authorization leads to GPO policies functioning inconsistently
vendor_redhat·2024-04-16·CVSS 7.1
CVE-2023-3758 [HIGH] CWE-362 sssd: Race condition during authorization leads to GPO policies functioning inconsistently
sssd: Race condition during authorization leads to GPO policies functioning inconsistently
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
Statement: This flaw is triggered by a race condition which makes it difficult to exploit. Also, it depends on non default GPO configuration on the server side. This two aspects lowers the severity of the issue to Moderate.
Mitigation: A mitigation can be applied to
Debian
CVE-2023-3758: sssd - A race condition flaw was found in sssd where the GPO policy is not consistently...
vendor_debian·2023·CVSS 7.1
CVE-2023-3758 [HIGH] CVE-2023-3758: sssd - A race condition flaw was found in sssd where the GPO policy is not consistently...
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
Scope: local
bookworm: resolved (fixed in 2.8.2-4+deb12u1)
bullseye: resolved (fixed in 2.4.1-2+deb11u1)
forky: resolved (fixed in 2.9.5-1)
sid: resolved (fixed in 2.9.5-1)
trixie: resolved (fixed in 2.9.5-1)
OSV
CVE-2023-3758: A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users
osv·2024-04-18·CVSS 7.1
CVE-2023-3758 [HIGH] CVE-2023-3758: A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
GHSA
GHSA-7pwr-cfrc-px4f: A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users
ghsa_unreviewed·2024-04-18
CVE-2023-3758 [HIGH] CWE-285 GHSA-7pwr-cfrc-px4f: A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:1919https://access.redhat.com/errata/RHSA-2024:1920https://access.redhat.com/errata/RHSA-2024:1921https://access.redhat.com/errata/RHSA-2024:1922https://access.redhat.com/errata/RHSA-2024:2571https://access.redhat.com/errata/RHSA-2024:3270https://access.redhat.com/security/cve/CVE-2023-3758https://bugzilla.redhat.com/show_bug.cgi?id=2223762https://github.com/SSSD/sssd/pull/7302https://access.redhat.com/errata/RHSA-2024:1919https://access.redhat.com/errata/RHSA-2024:1920https://access.redhat.com/errata/RHSA-2024:1921https://access.redhat.com/errata/RHSA-2024:1922https://access.redhat.com/errata/RHSA-2024:2571https://access.redhat.com/errata/RHSA-2024:3270https://access.redhat.com/security/cve/CVE-2023-3758https://bugzilla.redhat.com/show_bug.cgi?id=2223762https://github.com/SSSD/sssd/pull/7302https://lists.debian.org/debian-lts-announce/2025/02/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/RV3HIZI3SURBUQKSOOL3XE64OOBQ2HTK/https://lists.fedoraproject.org/archives/list/[email protected]/message/XEP62IDS7A55D5UHM6GH7QZ7SQFOAPVF/https://lists.fedoraproject.org/archives/list/[email protected]/message/XMORAO2BDDA5YX4ZLMXDZ7SM6KU47SY5/
2024-04-18
Published