Search CVE reports


Toggle filters

1 – 10 of 29 results


CVE-2025-4404

Medium priority
Needs evaluation

A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create...

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-11029

Medium priority
Needs evaluation

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials,...

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-1271

Medium priority
Ignored

Rejected reason: This CVE was previously published at https://bugzilla.redhat.com/show_bug.cgi?id=2262978 but later rejected for the following reason: The flaw requires an attacker to have superuser credentials which is a...

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-3183

Medium priority
Needs evaluation

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it...

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-2698

Medium priority
Needs evaluation

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case...

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-1481

Medium priority
Needs evaluation

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-5455

Medium priority
Needs evaluation

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user,...

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-10747

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Not affected Not affected
Show less packages

CVE-2020-1722

Medium priority
Needs evaluation

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the...

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-14867

Medium priority
Vulnerable

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which...

1 affected package

freeipa

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Not affected Vulnerable Vulnerable Vulnerable
Show less packages