CVE-2022-4254
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
Affected (14)
Products: Fedoraproject: Sssd · Redhat: Enterprise Linux, Enterprise Linux Desktop, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Power Big Endian, Enterprise Linux For Power Little Endian, Enterprise Linux For Scientific Computing, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Enterprise Linux Workstation
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.15.3 to 2.3.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 8.2 | |
| Version 8.1 | |
| Version 8.2 | |
| Version 8.1 | |
| Version 7.0 |
References (10)
Source: secalert@redhat.com
ExploitIssue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
ExploitIssue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.