CVE-2021-3621

HIGH

SSSD - OS Command Injection via sssctl logs-fetch and cache-expire Subcommands

Title source: llm
STIX 2.1

Description

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

References (4)

Core 4

Scores

CVSS v3 8.8
EPSS 0.0038
EPSS Percentile 59.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-77
Status published
Products (13)
fedoraproject/fedora 34
fedoraproject/sssd 2.6.0
redhat/enterprise_linux 6.0
redhat/enterprise_linux 7.0
redhat/enterprise_linux 8.0
redhat/enterprise_linux_eus 8.1
redhat/enterprise_linux_eus 8.2
redhat/enterprise_linux_server_aus 8.2
redhat/enterprise_linux_server_aus 8.4
redhat/enterprise_linux_server_tus 8.2
... and 3 more
Published Dec 23, 2021
Tracked Since Feb 18, 2026