Fedora Account System
Red Hat Associate
Red Hat Customer
AI_ONLY_REPORT package: sssd-2.12.0-1.el10 ------ Summary: OData Filter Injection in Entra ID Lookup (`oidc_child_id.c`) Enables Overbroad Directory Queries: crafted lookup values containing single quotes can escape intended OData string literals and broaden Entra directory queries issued by the affected lookup path. Requirements to exploit: A low-privileged local actor must be able to trigger name-based lookups on a system that builds and uses the Entra ID provider path (`idp_type=entra_id`) with valid directory client credentials and scopes. No separate user interaction is required. Component affected: `sssd-2.12.0-1.el10`, `src/oidc_child/oidc_child_id.c`, `entra_id_lookup()`. Version affected: `sssd-2.12.0-1.el10` when the Entra ID provider path is built and deployed with `idp_type=entra_id`. Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L - 5.3 (MEDIUM) AV:L - The issue is reached through a local lookup path rather than direct remote network exposure. AC:L - A crafted lookup value containing a single quote is sufficient to alter the generated OData predicate. PR:L - The attacker needs low privileges sufficient to trigger account or group lookups on the affected system. UI:N - No additional user interaction is required once the lookup is issued. S:U - The impact stays within the same SSSD/IdP lookup security scope. C:L - Successful exploitation can return broader directory metadata than intended, but the exposed data depends on granted directory permissions and deployment details. I:L - The lookup predicate can be changed from the intended exact or prefix match to attacker-influenced logic. A:L - Overbroad responses can increase parsing, processing, and cache activity, but the available evidence does not establish reliable high-impact exhaustion in all environments. Impact: Moderate. This issue does not match Red Hat's Important or Critical guidance because it is not an unauthenticated remote compromise path and depends on a specific Entra ID configuration. In affected deployments, however, a low-privileged local actor can change query logic, potentially obtain broader directory results than intended, and drive additional processing or cache pressure. That supports a configuration-dependent compromise of confidentiality, integrity, and availability consistent with a Moderate rating. Embargo: no Reason: The issue is locally triggered, configuration-dependent, and the demonstrated impact is overbroad queries plus extra processing rather than remote system compromise. A straightforward code fix exists, so normal coordinated disclosure is appropriate. Acknowledgement: Aisle Research Vulnerability Details: In `sssd-2.12.0-1.el10`, the Entra ID lookup path builds OData `$filter` expressions by inserting user-controlled `input` into single-quoted literals without escaping embedded single quotes: ```c filter = talloc_asprintf(rest_ctx, "startsWith(userPrincipalName,'%s@')", input); filter = talloc_asprintf(rest_ctx, "mail eq '%s' or userPrincipalName eq '%s'", input, input); filter = talloc_asprintf(rest_ctx, "displayName eq '%s'", input); filter = talloc_asprintf(rest_ctx, "displayName eq '%s' or displayName eq '%s'", input, short_name); ``` Only URL encoding is applied afterward: ```c filter_enc = url_encode_string(rest_ctx, filter); ``` The observed call path shows that the lookup value is forwarded into `--name=%s`, `sss_parse_internal_fqname()` does not remove quote characters, and returned arrays are later iterated and stored in cache. Based on that behavior, a crafted lookup value containing `'` can terminate the intended OData string literal and append additional predicate logic after the request is decoded by the server. The available evidence supports overbroad directory queries and additional backend processing in affected Entra ID deployments. It does not establish arbitrary code execution, and the maximum disclosure or availability impact will vary with configuration, granted directory permissions, and server-side response limits such as paging. Steps to reproduce: 1. Configure the affected package to use the IdP provider with `idp_type=entra_id` and valid directory client credentials/scopes. 2. Trigger a name-based lookup with a crafted value containing a single quote, for example `a') or startsWith(userPrincipalName,'') or ('1' eq '1`. 3. Enable SSSD debug logging or `--libcurl-debug` and inspect the outgoing request to the directory `/users?$filter=` or `/groups?$filter=` endpoint. 4. Confirm that, after URL decoding, the generated `$filter` contains injected `or ...` logic instead of a single intended literal comparison or prefix test. 5. Compare the response and downstream processing against a benign lookup and observe that the injected request can return a broader result set that is then iterated and stored by the IdP evaluation path. Mitigation: Until a package fix is available, avoid enabling the Entra ID provider path where it is not required. Where Entra ID integration is required, restrict who can trigger name-based lookups with untrusted input and monitor for unexpectedly broad directory `$filter` requests. These measures reduce exposure but do not eliminate the underlying flaw. Proposed Fix: Escape single quotes in OData string literals before interpolation so that lookup values cannot break out of the intended literal. The following minimal patch addresses the affected construction sites: ```diff diff --git a/src/oidc_child/oidc_child_id.c b/src/oidc_child/oidc_child_id.c — a/src/oidc_child/oidc_child_id.c +++ b/src/oidc_child/oidc_child_id.c @@ +static char *odata_escape_single_quotes(TALLOC_CTX *mem_ctx, const char *in) +{ + size_t i; + char *out = NULL; + + if (in == NULL) return NULL; + out = talloc_strdup(mem_ctx, ""); + if (out == NULL) return NULL; + + for (i = 0; in[i] != '\0'; i++) { + out = (in[i] == '\'') ? talloc_asprintf_append(out, "''") + : talloc_asprintf_append(out, "%c", in[i]); + if (out == NULL) return NULL; + } + return out; +} @@ char *filter; + char *filter; + char *input_esc = NULL; + char *short_name_esc = NULL; @@ + input_esc = odata_escape_single_quotes(rest_ctx, input); + if (input_esc == NULL) { ret = ENOMEM; goto done; } @@ filter = talloc_asprintf(rest_ctx, "startsWith(userPrincipalName,'%s@')", input); + filter = talloc_asprintf(rest_ctx, "startsWith(userPrincipalName,'%s@')", input_esc); @@ input, input); + input_esc, input_esc); @@ filter = talloc_asprintf(rest_ctx, "displayName eq '%s'", input); + filter = talloc_asprintf(rest_ctx, "displayName eq '%s'", input_esc); @@ filter = talloc_asprintf(rest_ctx, "displayName eq '%s'", input); + filter = talloc_asprintf(rest_ctx, "displayName eq '%s'", input_esc); } else { + short_name_esc = odata_escape_single_quotes(rest_ctx, short_name); + if (short_name_esc == NULL) { ret = ENOMEM; goto done; } filter = talloc_asprintf(rest_ctx, "displayName eq '%s' or displayName eq '%s'", input, short_name); + input_esc, short_name_esc); } ``` ------ This report was generated using AI technology. Always review AI-generated content prior to use