GHSA-58vh-w7mf-682fMediumCVSS 5.4
A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order`...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in SSSD. When configured with the LDAP access provider and ldap_access_order including ppolicy or lockout, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued authorization for a deleted or deprovisioned user. A remote attacker with prior valid account context could exploit this to maintain access to information and potentially make limited modifications to resources that should no longer be available.