A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade ipa-client-epnUpgrade ipa-server-trust-adUpgrade ipa-selinuxUpgrade ipa-client-sambaUpgrade ipa-commonUpgrade python3-ipatestsUpgrade python3-ipaserverUpgrade ipa-client-commonUpgrade ipa-serverUpgrade python3-ipaclientUpgrade ipa-clientUpgrade ipa-server-dnsUpgrade python3-ipalibUpgrade ipa-server-common | May 8, 2024 | Apr 10, 2024 |
| Amazon Linux Ami 2 | — | Upgrade ipa-clientUpgrade ipa-server-commonUpgrade ipa-client-commonUpgrade ipa-debuginfoUpgrade python2-ipaclientUpgrade ipa-server-trust-adUpgrade ipa-commonUpgrade python2-ipaserverUpgrade ipa-serverUpgrade ipa-server-dnsUpgrade python2-ipalibUpgrade ipa-python-compat | Mar 19, 2024 | Mar 19, 2024 |
| Debian | — | Upgrade freeipa | Mar 26, 2024 | Mar 26, 2024 |
| Oracle_linux | — | Upgrade ipa-python-compatUpgrade ipa-commonUpgrade python3-qrcode-coreUpgrade ipa-healthcheckUpgrade ipa-server-commonUpgrade python3-ipatestsUpgrade python3-ipaclientUpgrade ipa-serverUpgrade ipa-client-commonUpgrade python3-jwcryptoUpgrade python3-custodiaUpgrade python3-yubicoUpgrade opendnssecUpgrade softhsm-develUpgrade ipa-client-epnUpgrade python3-ipaserverUpgrade softhsmUpgrade ipa-clientUpgrade ipa-client-sambaUpgrade bind-dyndb-ldapUpgrade ipa-selinuxUpgrade python3-kdcproxyUpgrade custodiaUpgrade ipa-healthcheck-coreUpgrade python3-pyusbUpgrade python3-ipalibUpgrade ipa-server-dnsUpgrade python3-qrcodeUpgrade slapi-nisUpgrade ipa-server-trust-ad | May 7, 2024 | Feb 20, 2024 |
| Redhat_linux | — | Upgrade softhsm-debuginfoUpgrade slapi-nisUpgrade ipa-client-sambaUpgrade custodiaUpgrade python3-ipatestsUpgrade python3-jwcryptoUpgrade ipa-serverUpgrade bind-dyndb-ldap-debugsourceUpgrade python3-ipaserverUpgrade ipa-debuginfoUpgrade ipa-commonUpgrade bind-dyndb-ldap-debuginfoUpgrade opendnssec-debuginfoUpgrade ipa-selinuxUpgrade python3-ipaclientUpgrade ipa-clientUpgrade softhsm-develUpgrade bind-dyndb-ldapUpgrade ipa-healthcheckUpgrade slapi-nis-debuginfoUpgrade python3-yubicoUpgrade ipa-client-epnUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-server-trust-adUpgrade python3-qrcode-coreUpgrade ipa-python-compatUpgrade ipa-server-commonUpgrade ipa-server-debuginfoUpgrade ipa-server-dnsUpgrade softhsm-debugsourceNo solution existsUpgrade ipa-debugsourceUpgrade ipa-client-commonUpgrade ipa-healthcheck-coreUpgrade ipa-client-debuginfoUpgrade opendnssecUpgrade slapi-nis-debugsourceUpgrade python3-ipalibUpgrade opendnssec-debugsourceUpgrade softhsmUpgrade python3-custodiaUpgrade python3-pyusbUpgrade python3-kdcproxyUpgrade python3-qrcode | May 1, 2024 | Apr 10, 2024 |
| Rocky_linux | — | Upgrade softhsm-debugsourceUpgrade softhsm-debuginfoUpgrade opendnssec-debuginfoUpgrade slapi-nis-debugsourceUpgrade softhsmUpgrade opendnssec-debugsourceUpgrade slapi-nisUpgrade slapi-nis-debuginfoUpgrade softhsm-develUpgrade opendnssec | Jun 17, 2024 | Apr 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub