PublicDateAtUSN: 2019-03-25 18:29:00 UTC Candidate: CVE-2018-16838 PublicDate: 2019-03-25 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16838 https://ubuntu.com/security/notices/USN-5067-1 Description: A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access. Ubuntu-Description: Notes: mdeslaur> introduced in https://github.com/SSSD/sssd/commit/60cab26b12 Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=1640820 Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N [5.4 MEDIUM] Patches_sssd: upstream: https://pagure.io/SSSD/sssd/c/ad058011b6b75b15c674be46a3ae9b3cc5228175 upstream_sssd: released (2.2.0-1) precise/esm_sssd: DNE trusty_sssd: ignored (reached end-of-life) trusty/esm_sssd: DNE (trusty was deferred [2019-04-23]) xenial_sssd: ignored (end of standard support, was needed) esm-infra/xenial_sssd: needed bionic_sssd: released (1.16.1-1ubuntu1.8) cosmic_sssd: ignored (reached end-of-life) disco_sssd: ignored (reached end-of-life) eoan_sssd: not-affected (2.2.0-4ubuntu1) focal_sssd: not-affected (2.2.2-1) groovy_sssd: not-affected (2.2.2-1) hirsute_sssd: not-affected (2.2.2-1) impish_sssd: not-affected (2.2.2-1) jammy_sssd: not-affected (2.2.2-1) devel_sssd: not-affected (2.2.2-1)