Freeipa

Freeipa

20 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Published 12.06.2024 08:15:50
  • Last modified 24.11.2024 17:15:04

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed...

  • EPSS 0.25%
  • Published 10.04.2024 21:15:06
  • Last modified 21.11.2024 08:50:40

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

  • EPSS 0.37%
  • Published 10.01.2024 13:15:48
  • Last modified 21.11.2024 08:41:47

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of ...

  • EPSS 0.37%
  • Published 27.04.2020 21:15:13
  • Last modified 21.11.2024 05:11:14

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unr...

  • EPSS 2.73%
  • Published 27.11.2019 09:15:10
  • Last modified 21.11.2024 04:27:32

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data....

  • EPSS 0.72%
  • Published 27.11.2019 08:15:10
  • Last modified 21.11.2024 04:18:37

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on Fre...

  • EPSS 0.51%
  • Published 25.11.2019 15:15:11
  • Last modified 21.11.2024 01:45:00

ipa 3.0 does not properly check server identity before sending credential containing cookies

  • EPSS 0.11%
  • Published 17.09.2019 16:15:10
  • Last modified 21.11.2024 04:27:26

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

  • EPSS 0.18%
  • Published 27.07.2018 18:29:00
  • Last modified 21.11.2024 03:23:47

A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable,...

  • EPSS 0.27%
  • Published 13.03.2018 13:29:00
  • Last modified 21.11.2024 03:01:25

Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify p...