8.8

CVE-2017-11191

FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freeipa ≫ Freeipa Version 4.0.0
Freeipa ≫ Freeipa Version 4.0.1
Freeipa ≫ Freeipa Version 4.0.2
Freeipa ≫ Freeipa Version 4.0.3
Freeipa ≫ Freeipa Version 4.0.4
Freeipa ≫ Freeipa Version 4.0.5
Freeipa ≫ Freeipa Version 4.1.0
Freeipa ≫ Freeipa Version 4.1.1
Freeipa ≫ Freeipa Version 4.1.2
Freeipa ≫ Freeipa Version 4.1.3
Freeipa ≫ Freeipa Version 4.1.4
Freeipa ≫ Freeipa Version 4.2.0
Freeipa ≫ Freeipa Version 4.2.1
Freeipa ≫ Freeipa Version 4.2.2
Freeipa ≫ Freeipa Version 4.2.3
Freeipa ≫ Freeipa Version 4.2.4
Freeipa ≫ Freeipa Version 4.3.0
Freeipa ≫ Freeipa Version 4.3.1
Freeipa ≫ Freeipa Version 4.3.2
Freeipa ≫ Freeipa Version 4.3.3
Freeipa ≫ Freeipa Version 4.4.0
Freeipa ≫ Freeipa Version 4.4.1
Freeipa ≫ Freeipa Version 4.4.2
Freeipa ≫ Freeipa Version 4.4.3
Freeipa ≫ Freeipa Version 4.4.4
Freeipa ≫ Freeipa Version 4.5.0
Freeipa ≫ Freeipa Version 4.5.1
Freeipa ≫ Freeipa Version 4.5.2
Freeipa ≫ Freeipa Version 4.5.3
Freeipa ≫ Freeipa Version 4.6.0
Freeipa ≫ Freeipa Version 4.6.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.69% 0.74
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-384 Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

http://packetstormsecurity.com/files/143532/FreeIPA-2.213-Session-Hijacking.html
Third Party Advisory
VDB Entry