CVE-2023-7090: Sudo Project Sudo
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.
Affected products
- Sudo Project Sudo: before 1.8.28 (fixed in 1.8.28)
Published 2023-12-23. Last modified 2026-06-17.