Bug 1189492 (CVE-2021-3621) - VUL-0: CVE-2021-3621: sssd: shell command injection in sssctl
Summary: VUL-0: CVE-2021-3621: sssd: shell command injection in sssctl
Status: RESOLVED FIXED
Alias: CVE-2021-3621
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/307324/
Whiteboard: CVSSv3.1:SUSE:CVE-2021-3621:6.7:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2021-08-17 06:51 UTC by Robert Frohl
Modified: 2024-07-16 15:40 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2021-08-17 06:51:10 UTC
rh#1975142

`sssctl_run_command()` is a wrapper for running commands via a shell, using glibc's `system()` function call.
`sssctl_cache_expire()` and `sssctl_logs_fetch()` allow user provided arguments, and pass them to `sssctl_run_command()`
sssctl is limited to root user, however, if an administrator allows unprivileged users to provide arguments to the command (e.g.: via sudo), this could be used to elevate privileges via a shell injection.

Although there are no known default configuration where this flaw could be exploited, the admin could have manually created sudo rules to let regular users use sssctl commands, or could be tricked into running a specially crafted sssctl command.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1975142
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-3621
https://access.redhat.com/errata/RHSA-2021:3151.html
Comment 2 Robert Frohl 2021-08-17 07:04:35 UTC
tracking a affected:

- SUSE:SLE-12-SP4:Update/sssd
- SUSE:SLE-12-SP5:Update/sssd
- SUSE:SLE-15:Update/sssd
- SUSE:SLE-15-SP2:Update/sssd
- SUSE:SLE-15-SP3:Update/sssd
Comment 4 Swamp Workflow Management 2021-08-30 19:30:38 UTC
# maintenance_jira_update_notice
SUSE-SU-2021:2873-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1189492
CVE References: CVE-2021-3621
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    sssd-1.16.1-7.22.4
SUSE Linux Enterprise Server 12-SP5 (src):    sssd-1.16.1-7.22.4

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Swamp Workflow Management 2021-09-03 13:27:28 UTC
# maintenance_jira_update_notice
SUSE-SU-2021:2941-1: An update that solves one vulnerability and has two fixes is now available.

Category: security (important)
Bug References: 1183735,1187120,1189492
CVE References: CVE-2021-3621
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    sssd-1.16.1-23.11.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2021-09-03 13:31:00 UTC
# maintenance_jira_update_notice
openSUSE-SU-2021:2941-1: An update that solves one vulnerability and has two fixes is now available.

Category: security (important)
Bug References: 1183735,1187120,1189492
CVE References: CVE-2021-3621
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    sssd-1.16.1-23.11.1
Comment 8 Swamp Workflow Management 2021-09-22 16:23:42 UTC
SUSE-RU-2021:3185-1: An update that solves one vulnerability, contains one feature and has 5 fixes is now available.

Category: recommended (moderate)
Bug References: 1182058,1182637,1184289,1187120,1189492,1190021
CVE References: CVE-2021-3621
JIRA References: ECO-3493
Sources used:
SUSE Linux Enterprise Module for Basesystem 15-SP2 (src):    sssd-1.16.1-17.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2021-09-28 13:22:49 UTC
openSUSE-RU-2021:1315-1: An update that solves one vulnerability, contains one feature and has 5 fixes is now available.

Category: recommended (moderate)
Bug References: 1182058,1182637,1184289,1187120,1189492,1190021
CVE References: CVE-2021-3621
JIRA References: ECO-3493
Sources used:
openSUSE Leap 15.2 (src):    sssd-1.16.1-lp152.16.3.1
Comment 10 Samuel Cabrero 2021-11-24 16:18:19 UTC
Reassign to security team to close it.
Comment 15 Swamp Workflow Management 2022-03-14 17:22:16 UTC
SUSE-SU-2022:0826-1: An update that solves one vulnerability and has two fixes is now available.

Category: security (important)
Bug References: 1182637,1189492,1190775
CVE References: CVE-2021-3621
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    sssd-1.16.1-8.64.1
SUSE Linux Enterprise Server for SAP 15 (src):    sssd-1.16.1-8.64.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    sssd-1.16.1-8.64.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    sssd-1.16.1-8.64.1
SUSE Linux Enterprise Server 15-LTSS (src):    sssd-1.16.1-8.64.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    sssd-1.16.1-8.64.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    sssd-1.16.1-8.64.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    sssd-1.16.1-8.64.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    sssd-1.16.1-8.64.1
SUSE Enterprise Storage 6 (src):    sssd-1.16.1-8.64.1
SUSE CaaS Platform 4.0 (src):    sssd-1.16.1-8.64.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Swamp Workflow Management 2022-04-19 13:27:42 UTC
SUSE-SU-2022:1258-1: An update that solves one vulnerability, contains one feature and has two fixes is now available.

Category: security (important)
Bug References: 1183735,1189492,1196564
CVE References: CVE-2021-3621
JIRA References: SLE-17773
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    sssd-1.16.1-4.40.1
SUSE OpenStack Cloud 9 (src):    sssd-1.16.1-4.40.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    sssd-1.16.1-4.40.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    sssd-1.16.1-4.40.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Samuel Cabrero 2022-05-10 09:06:46 UTC
Reassign to security team to close it.
Comment 19 Robert Frohl 2022-05-10 09:08:20 UTC
done
Comment 20 Swamp Workflow Management 2022-08-10 16:23:53 UTC
SUSE-SU-2022:2763-1: An update that solves one vulnerability and has four fixes is now available.

Category: security (moderate)
Bug References: 1182058,1189492,1190775,1195552,1196166
CVE References: CVE-2021-3621
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    sssd-2.5.2-150400.4.5.14
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    sssd-2.5.2-150400.4.5.14

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.