Freeipa

Freeipa

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 12.06.2024 08:15:50
  • Zuletzt bearbeitet 24.11.2024 17:15:04

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed...

  • EPSS 0.25%
  • Veröffentlicht 10.04.2024 21:15:06
  • Zuletzt bearbeitet 21.11.2024 08:50:40

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

  • EPSS 0.37%
  • Veröffentlicht 10.01.2024 13:15:48
  • Zuletzt bearbeitet 21.11.2024 08:41:47

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of ...

  • EPSS 0.37%
  • Veröffentlicht 27.04.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:14

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unr...

  • EPSS 2.73%
  • Veröffentlicht 27.11.2019 09:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:32

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data....

  • EPSS 0.72%
  • Veröffentlicht 27.11.2019 08:15:10
  • Zuletzt bearbeitet 21.11.2024 04:18:37

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on Fre...

  • EPSS 0.51%
  • Veröffentlicht 25.11.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 01:45:00

ipa 3.0 does not properly check server identity before sending credential containing cookies

  • EPSS 0.11%
  • Veröffentlicht 17.09.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:26

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

  • EPSS 0.18%
  • Veröffentlicht 27.07.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:47

A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable,...

  • EPSS 0.27%
  • Veröffentlicht 13.03.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:01:25

Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify p...