Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-3621
Description:A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2021.2873.1   1.3.6.1.4.1.25623.1.1.2.2021.2646   1.3.6.1.4.1.25623.1.1.2.2021.2767   1.3.6.1.4.1.25623.1.0.879982   1.3.6.1.4.1.25623.1.1.2.2021.2826   1.3.6.1.4.1.25623.1.1.2.2021.2699   1.3.6.1.4.1.25623.1.1.2.2022.1097   1.3.6.1.4.1.25623.1.1.2.2022.1148   1.3.6.1.4.1.25623.1.0.883374   1.3.6.1.4.1.25623.1.1.2.2021.2675   1.3.6.1.4.1.25623.1.1.4.2021.2941.1   1.3.6.1.4.1.25623.1.0.854137   1.3.6.1.4.1.25623.1.1.2.2021.2739   1.3.6.1.4.1.25623.1.1.4.2022.0826.1   1.3.6.1.4.1.25623.1.1.2.2023.1295   1.3.6.1.4.1.25623.1.1.2.2021.2724   1.3.6.1.4.1.25623.1.1.4.2022.1258.1   1.3.6.1.4.1.25623.1.1.4.2022.2763.1   1.3.6.1.4.1.25623.1.1.10.2021.0502   1.3.6.1.4.1.25623.1.0.854895   1.3.6.1.4.1.25623.1.0.892758   1.3.6.1.4.1.25623.1.0.817761   1.3.6.1.4.1.25623.1.1.1.2.2023.3436   1.3.6.1.4.1.25623.1.1.2.2021.2880  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-3621
https://bugzilla.redhat.com/show_bug.cgi?id=1975142
https://bugzilla.redhat.com/show_bug.cgi?id=1975142
https://sssd.io/release-notes/sssd-2.6.0.html
https://sssd.io/release-notes/sssd-2.6.0.html
https://lists.debian.org/debian-lts-announce/2023/05/msg00028.html




© 1998-2025 E-Soft Inc. All rights reserved.