Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2017-11191

Disclosure Date: September 28, 2017 (last updated November 08, 2023)
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern
0
Attacker Value
Unknown

CVE-2015-5284

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
0
Attacker Value
Unknown

CVE-2015-5179

Disclosure Date: September 20, 2017 (last updated November 26, 2024)
FreeIPA might display user data improperly via vectors involving non-printable characters.
0
Attacker Value
Unknown

CVE-2016-7030

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.
0
Attacker Value
Unknown

CVE-2016-5414

Disclosure Date: June 27, 2017 (last updated November 26, 2024)
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
0
Attacker Value
Unknown

CVE-2016-5404

Disclosure Date: September 07, 2016 (last updated November 25, 2024)
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
0
Attacker Value
Unknown

CVE-2015-1827

Disclosure Date: March 30, 2015 (last updated October 05, 2023)
The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.
0
Attacker Value
Unknown

CVE-2014-7850

Disclosure Date: November 28, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.
0
Attacker Value
Unknown

CVE-2014-7828

Disclosure Date: November 19, 2014 (last updated October 05, 2023)
FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.
0
Attacker Value
Unknown

CVE-2013-0336

Disclosure Date: November 03, 2014 (last updated October 05, 2023)
The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection request without a username/dn, related to the 389 directory server.
0