Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function in src/providers/idp/idp_auth_eval.c compares the authenticated user's OIDC subject identifier against the requested user's stored SYSDB_UUID using strncmp() with the authenticated identifier's length as the count. This performs a prefix comparison rather than an exact match. An attacker whose complete IdP identifier is a strict prefix of a target user's identifier can authenticate as the target, gaining full access to the target's account, files, groups, and local authorization. With Keycloak's built-in LDAP provider (Import Users disabled), the identifier format f:<federation_id>:<username> naturally produces prefix relationships for usernames like 'admin' and 'administrator'. No victim credential, interaction, or administrative role is required.