Vulnerability Description
Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Authconfig Project | Authconfig | 6.2.8 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101784
- https://access.redhat.com/errata/RHSA-2017:2285
- https://bugzilla.redhat.com/show_bug.cgi?id=1441604Issue TrackingPatchThird Party Advisory
- https://pagure.io/authconfig/c/0972f61ad4b5657ed89cf953e8f58f6513096224?branch=mPatchThird Party Advisory
- http://www.securityfocus.com/bid/101784
- https://access.redhat.com/errata/RHSA-2017:2285
- https://bugzilla.redhat.com/show_bug.cgi?id=1441604Issue TrackingPatchThird Party Advisory
- https://pagure.io/authconfig/c/0972f61ad4b5657ed89cf953e8f58f6513096224?branch=mPatchThird Party Advisory
FAQ
What is CVE-2017-7488?
CVE-2017-7488 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames.
How severe is CVE-2017-7488?
CVE-2017-7488 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7488?
Check the references section above for vendor advisories and patch information. Affected products include: Authconfig Project Authconfig.