Database/Control plane, storage & DevOps

Samba (AD DC): KDC and kpasswd share keys
CVSS 8.8CVE-2022-2031Control plane, storage & DevOpscurated
Impact
KDC and kpasswd share keys -> a user forced to change password can obtain tickets to other services
Who can reach it
Network (remote)
What to do
Control-plane: DC-only upgrade
References
Related entries
- Samba (AD DC): KDC accepts kpasswd requests encrypted with any key it knowsCVE-2022-32744 · Samba (AD DC)High
- Intel Data Center Manager: Improper access control in Data Center Manager lets an unauthenticated attackerCVE-2022-23182 · Intel Data Center ManagerHigh
- MinIO: Non-admin user can create service accounts for root/admin users and assume their policiesCVE-2022-24842 · MinIOHigh
- HTCondor (CLAIMTOBE authentication method): Once a user has authenticated to a daemon with CLAIMTOBE - a method thatCVE-2022-26110 · HTCondor (CLAIMTOBE authentication method)High
- Honeywell Alerton Visual Logic, Ascent Control Module (ACM) and Compass 1.6.5: Unauthenticated program writesCVE-2022-30243 · Honeywell Alerton Visual Logic, Ascent Control Module (ACM) and Compass 1.6.5High
- Pure Storage Purity//FA and Purity//FB restricted shell (Python environment variables): A logged-in user manipulatesCVE-2022-32552 · Pure Storage Purity//FA and Purity//FB restricted shell (Python environment variables)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.