CyberRota Analysis
AI-GeneratedA vulnerability in SSSD allows authenticated users from trusted domains to bypass Host-Based Access Control (HBAC) rules by using short usernames that match those of authorized local accounts. This flaw can lead to unauthorized access to protected services or hosts, posing a risk to identity management environments. Organizations utilizing SSSD in trust-enabled setups should prioritize addressing this issue to mitigate potential security breaches.
Original NVD Description
A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares the same username as an authorized local account can bypass access policies and gain unauthorized access to protected services or hosts.
Related CVEs
Other vulnerabilities affecting the same vendor(s)