<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:50:53.442997+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:3151</id>
    <title>ALSA-2021:3151 — Important: sssd security update</title>
    <updated>2026-10-04T01:50:53.564695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: libsss_nss_idmap-devel</p>
<p>The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.</p>
<p>Security Fix(es):</p>
<p>* sssd: shell command injection in sssctl (CVE-2021-3621)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:3151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07637</id>
    <title>bdu:2023-07637</title>
    <updated>2026-10-04T01:50:53.564769+00:00</updated>
    <content>bdu:2023-07637</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0051</id>
    <title>certfr-2023-avi-0051 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-04T01:50:53.564787+00:00</updated>
    <content>certfr-2023-avi-0051</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0051"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258006</id>
    <title>EUVD-2026-258006</title>
    <updated>2026-10-04T01:50:53.564805+00:00</updated>
    <content>EUVD-2026-258006</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3621</id>
    <title>fkie_cve-2021-3621</title>
    <updated>2026-10-04T01:50:53.564816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g527-g4q2-57xc</id>
    <title>GHSA-g527-g4q2-57xc</title>
    <updated>2026-10-04T01:50:53.564840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g527-g4q2-57xc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3621</id>
    <title>gsd-2021-3621</title>
    <updated>2026-10-04T01:50:53.564855+00:00</updated>
    <content>gsd-2021-3621</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1340</id>
    <title>OESA-2021-1340 — sssd security update</title>
    <updated>2026-10-04T01:50:53.564864+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: sssd, openEuler:20.03-LTS-SP2: sssd</p>
<p>SSSD provides a set of daemons to manage access to remote directories and authentication mechanisms such as LDAP, Kerberos or FreeIPA. It provides an NSS and PAM interface toward the system and a pluggable backend system to connect to multiple different account sources.

Security Fix(es):

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2021-3621)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:2941-1</id>
    <title>openSUSE-SU-2021:2941-1 — Security update for sssd</title>
    <updated>2026-10-04T01:50:53.564890+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for sssd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:2941-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:3178</id>
    <title>RHSA-2021:3178 — Red Hat Security Advisory: sssd security update</title>
    <updated>2026-10-04T01:50:53.564907+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sssd: shell command injection in sssctl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:3178"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2021:3185-1</id>
    <title>SUSE-RU-2021:3185-1 — Recommended update for sssd</title>
    <updated>2026-10-04T01:50:53.564923+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for sssd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2021:3185-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3621</id>
    <title>UBUNTU-CVE-2021-3621</title>
    <updated>2026-10-04T01:50:53.564936+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: sssd, Ubuntu:20.04:LTS: sssd, Ubuntu:22.04:LTS: sssd</p>
<p>A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1001</id>
    <title>WID-SEC-W-2022-1001 — Red Hat Enterprise Linux: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten</title>
    <updated>2026-10-04T01:50:53.564959+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1001"/>
  </entry>
</feed>
