Hide Forgot
`sssctl_run_command()` is a wrapper for running commands via a shell, using glibc's `system()` function call. `sssctl_cache_expire()` and `sssctl_logs_fetch()` allow user provided arguments, and pass them to `sssctl_run_command()` sssctl is limited to root user, however, if an administrator allows unprivileged users to provide arguments to the command (e.g.: via sudo), this could be used to elevate privileges via a shell injection. Although there are no known default configuration where this flaw could be exploited, the admin could have manually created sudo rules to let regular users use sssctl commands, or could be tricked into running a specially crafted sssctl command. References: https://sssd.io/release-notes/sssd-2.6.0.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:3151 https://access.redhat.com/errata/RHSA-2021:3151
Created sssd tracking bugs for this issue: Affects: fedora-all [bug 1993910]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-3621
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Extended Update Support Via RHSA-2021:3178 https://access.redhat.com/errata/RHSA-2021:3178
This issue has been addressed in the following products: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Via RHSA-2021:3235 https://access.redhat.com/errata/RHSA-2021:3235
Upstream fix : https://github.com/SSSD/sssd/commit/7ab83f97e1cbefb78ece17232185bdd2985f0bbe
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2021:3336 https://access.redhat.com/errata/RHSA-2021:3336
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2021:3365 https://access.redhat.com/errata/RHSA-2021:3365
This issue has been addressed in the following products: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 Via RHSA-2021:3477 https://access.redhat.com/errata/RHSA-2021:3477