Impact
SSSD’s LDAP sudo provider flaw causes an unconfigured ldap_sudo_search_base to trigger a full directory tree scan for sudoRole objects. An authenticated attacker with write access to any LDAP subtree can inject a sudoRole object, granting root‑level sudo rights on every host where SSSD is enrolled, which provides the attacker complete administrative control across the infrastructure.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux versions 6 through 10 and the OpenShift Container Platform 4 family. All editions of these products that contain the affected SSSD version are susceptible, as the specific impacted SSSD releases are not listed in the CNA data.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of < 1% reflects a very low probability of exploitation, however, in environments with broad LDAP write privileges the risk still exists. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an LDAP account that can write objects to the directory; attackers who already have such permissions can create or modify sudoRole entries and elevate privileges. The risk remains significant for environments where LDAP write access is granted broadly or where SSSD is used without explicit search base restrictions.
OpenCVE Enrichment