8.8

CVE-2017-11191

FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern

Data is provided by the National Vulnerability Database (NVD)
FreeipaFreeipa Version4.0.0
FreeipaFreeipa Version4.0.1
FreeipaFreeipa Version4.0.2
FreeipaFreeipa Version4.0.3
FreeipaFreeipa Version4.0.4
FreeipaFreeipa Version4.0.5
FreeipaFreeipa Version4.1.0
FreeipaFreeipa Version4.1.1
FreeipaFreeipa Version4.1.2
FreeipaFreeipa Version4.1.3
FreeipaFreeipa Version4.1.4
FreeipaFreeipa Version4.2.0
FreeipaFreeipa Version4.2.1
FreeipaFreeipa Version4.2.2
FreeipaFreeipa Version4.2.3
FreeipaFreeipa Version4.2.4
FreeipaFreeipa Version4.3.0
FreeipaFreeipa Version4.3.1
FreeipaFreeipa Version4.3.2
FreeipaFreeipa Version4.3.3
FreeipaFreeipa Version4.4.0
FreeipaFreeipa Version4.4.1
FreeipaFreeipa Version4.4.2
FreeipaFreeipa Version4.4.3
FreeipaFreeipa Version4.4.4
FreeipaFreeipa Version4.5.0
FreeipaFreeipa Version4.5.1
FreeipaFreeipa Version4.5.2
FreeipaFreeipa Version4.5.3
FreeipaFreeipa Version4.6.0
FreeipaFreeipa Version4.6.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.225
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-384 Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.