CVE-2021-3621
—CVSS 3.1
8.8 high
EPSS
3%p84
Published
()
Modified
Description
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
- Vendors
- fedoraprojectredhat
- Products
- sssd, virtualization, virtualization host, enterprise linux, enterprise linux eus, enterprise linux server aus, enterprise linux server tus, fedora
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.