The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ipa-pythonUpgrade ipa-clientUpgrade ipa-serverUpgrade ipa-admintoolsUpgrade ipa-server-selinux | Dec 1, 2016 | Jan 27, 2013 |
| Oracle_linux | — | Upgrade ipa-serverUpgrade ipa-clientUpgrade ipa-pythonUpgrade ipa-admintoolsUpgrade ipa-server-selinux | Oct 16, 2024 | Jan 27, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub