Freeipa

Freeipa

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.7%
  • Veröffentlicht 28.08.2017 15:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.

  • EPSS 1.03%
  • Veröffentlicht 27.06.2017 20:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.

  • EPSS 2.59%
  • Veröffentlicht 07.09.2016 20:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

  • EPSS 2.64%
  • Veröffentlicht 30.03.2015 14:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user th...

  • EPSS 1.86%
  • Veröffentlicht 28.11.2014 15:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.

  • EPSS 2.07%
  • Veröffentlicht 19.11.2014 18:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.