Search CVE reports


Toggle filters

21 – 29 of 29 results


CVE-2016-5414

Low priority
Not affected

FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa
Show less packages

CVE-2016-5404

Low priority

Some fixes available 1 of 3

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Not affected Not affected Not affected
Show less packages

CVE-2015-1827

Medium priority
Not affected

The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list...

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa
Show less packages

CVE-2014-8105

Medium priority
Ignored

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog...

2 affected packages

389-ds-base, freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
389-ds-base Not affected
freeipa Not affected
Show less packages

CVE-2014-7850

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Not affected
Show less packages

CVE-2014-7828

High priority
Ignored

FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Not affected
Show less packages

CVE-2013-0199

Medium priority
Not affected

The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via...

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa
Show less packages

CVE-2013-0336

Medium priority
Ignored

The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection request...

2 affected packages

389-ds-base, freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
389-ds-base
freeipa
Show less packages

CVE-2012-5484

Medium priority
Ignored

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa
Show less packages