CVE Published: 15/01/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: redhat |
Vendor: The sssd Project |
Product: sssd Status : PUBLISHED
CVE-2019-3811 Description
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return \'/\' (the root directory) instead of \'\' (the empty string / no home directory). This could impact services that restrict the user\'s filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.