#458 SSSD needs to sanitize LDAP attribute options
Closed: Fixed Opened by sgallagh.

While there is at present no security risk, it was noted in https://bugzilla.redhat.com/show_bug.cgi?id=587743 that it is possible to perform an "LDAP injection" to the attribute options (such as

ldap_user_object_class = posixAccount)(Host=la1.prd.core.mgmt.shell.linux

We should probably guarantee that no parentheses appear in these options.


Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.3

Fields changed

milestone: SSSD 1.4.0 => SSSD Deferred
owner: simo => sgallagh
priority: major => trivial

Fields changed

milestone: SSSD Deferred => SSSD 1.5.0

Fields changed

priority: trivial => major

Fields changed

status: new => assigned

Fixed by be434625437ff3dd4cce83a655226c67943e5ceb

fixedin: => 1.5.0
resolution: => fixed
status: assigned => closed

Fields changed

rhbz: => [https://bugzilla.redhat.com/show_bug.cgi?id=587743 587743]

Metadata Update from @sgallagh:
- Issue assigned to sgallagh
- Issue set to the milestone: SSSD 1.5.0

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/1500

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata