CVE-2023-7090
CVSS V2 None
CVSS V3 None
Description
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.
Overview
- CVE ID
- CVE-2023-7090
- Assigner
- redhat
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-12-23T22:33:13.530Z
- Last Modified Date
- 2024-03-20T11:05:45.902Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2023-7090 | vdb-entry x_refsource_REDHAT |
https://bugzilla.redhat.com/show_bug.cgi?id=2255723 | issue-tracking x_refsource_REDHAT |
https://lists.debian.org/debian-lts-announce/2024/02/msg00002.html | |
https://security.netapp.com/advisory/ntap-20240208-0001/ | |
https://www.sudo.ws/releases/legacy/#1.8.28 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-7090 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7090 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 02:49:42 | Added to TrackCVE |