Freeipa

Freeipa

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 10:39:08
  • Zuletzt bearbeitet 24.08.2026 18:14:09

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible b...

  • EPSS -
  • Veröffentlicht 20.08.2026 10:39:00
  • Zuletzt bearbeitet 24.08.2026 18:19:56

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory e...

  • EPSS -
  • Veröffentlicht 20.08.2026 10:37:55
  • Zuletzt bearbeitet 24.08.2026 17:58:31

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a ...

  • EPSS -
  • Veröffentlicht 20.08.2026 10:31:58
  • Zuletzt bearbeitet 24.08.2026 17:49:31

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming exces...

  • EPSS -
  • Veröffentlicht 20.08.2026 10:31:31
  • Zuletzt bearbeitet 25.08.2026 15:16:41

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled req...

  • EPSS 0.19%
  • Veröffentlicht 11.08.2026 20:46:42
  • Zuletzt bearbeitet 25.08.2026 14:32:59

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Direc...

  • EPSS 0.67%
  • Veröffentlicht 12.06.2024 08:15:50
  • Zuletzt bearbeitet 24.11.2024 17:15:04

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed...

  • EPSS 1.11%
  • Veröffentlicht 10.04.2024 21:15:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

  • EPSS 0.57%
  • Veröffentlicht 10.01.2024 13:15:48
  • Zuletzt bearbeitet 18.03.2026 04:16:51

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of ...

  • EPSS 1.06%
  • Veröffentlicht 27.04.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:14

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unr...