Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://pagure.io/authconfig/c/0972f61ad4b5657ed89cf953e8f58f6513096224?branch=master | third party advisory patch |
http://www.securityfocus.com/bid/101784 | vdb entry |
https://access.redhat.com/errata/RHSA-2017:2285 | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1441604 | patch vdb entry third party advisory issue tracking |