CVE-2017-12173: Fedoraproject Sssd
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.
Affected products
- Fedoraproject Sssd: before 1.16.0 (fixed in 1.16.0)
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.4 only
- Red Hat Enterprise Linux Server Eus: version 7.4 only; version 7.5 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
Published 2018-07-27. Last modified 2026-06-17.