A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed_to_delegate() function: If the target service argument is NULL, then it means the KDC is probing for general constrained delegation rules and not checking a specific S4U2Proxy request. In FreeIPA 4.11.0, the behavior of ipadb_match_acl() was modified to match the changes from upstream MIT Kerberos 1.20. However, a mistake resulting in this mechanism applies in cases where the target service argument is set AND where it is unset. This results in S4U2Proxy requests being accepted regardless of whether or not there is a matching service delegation rule.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade ipa-client-sambaUpgrade slapi-nisUpgrade python3-ipatestsUpgrade python3-yubicoUpgrade python3-jwcryptoUpgrade python3-ipaserverUpgrade ipa-commonUpgrade ipa-healthcheckUpgrade ipa-serverUpgrade ipa-client-epnUpgrade ipa-selinuxUpgrade python3-ipaclientUpgrade ipa-server-trust-adUpgrade python3-qrcodeUpgrade ipa-client-commonUpgrade opendnssecUpgrade ipa-clientUpgrade python3-ipalibUpgrade softhsmUpgrade ipa-python-compatUpgrade ipa-healthcheck-coreUpgrade softhsm-develUpgrade python3-qrcode-coreUpgrade custodiaUpgrade python3-custodiaUpgrade ipa-server-commonUpgrade bind-dyndb-ldapUpgrade python3-kdcproxyUpgrade ipa-server-dnsUpgrade python3-pyusb | Jun 24, 2024 | Jun 12, 2024 |
| Debian | — | Upgrade freeipa | May 15, 2025 | Jun 12, 2024 |
| Oracle_linux | — | Upgrade python3-ipaclientUpgrade ipa-healthcheck-coreUpgrade ipa-client-commonUpgrade ipa-server-dnsUpgrade python3-qrcodeUpgrade ipa-client-epnUpgrade softhsmUpgrade python3-pyusbUpgrade python3-kdcproxyUpgrade bind-dyndb-ldapUpgrade ipa-server-trust-adUpgrade python3-ipaserverUpgrade ipa-client-sambaUpgrade ipa-serverUpgrade python3-custodiaUpgrade python3-ipatestsUpgrade python3-jwcryptoUpgrade ipa-python-compatUpgrade ipa-clientUpgrade ipa-healthcheckUpgrade custodiaUpgrade python3-qrcode-coreUpgrade python3-yubicoUpgrade opendnssecUpgrade ipa-server-commonUpgrade ipa-commonUpgrade softhsm-develUpgrade slapi-nisUpgrade python3-ipalibUpgrade ipa-selinux | Jul 22, 2024 | Jun 10, 2024 |
| Redhat_linux | — | Upgrade ipa-server-trust-adUpgrade python3-ipaclientUpgrade python3-ipalibUpgrade ipa-client-sambaUpgrade ipa-server-commonUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-selinuxUpgrade python3-ipatestsUpgrade ipa-debugsourceUpgrade ipa-client-debuginfoUpgrade ipa-client-epnNo solution existsUpgrade ipa-server-dnsUpgrade ipa-commonUpgrade python3-ipaserverUpgrade ipa-clientUpgrade ipa-debuginfoUpgrade ipa-serverUpgrade ipa-server-debuginfoUpgrade ipa-client-common | Jun 20, 2024 | Jun 12, 2024 |
| Rocky_linux | — | Upgrade ipa-server-trust-adUpgrade softhsm-develUpgrade ipa-clientUpgrade ipa-server-debuginfoUpgrade slapi-nisUpgrade opendnssec-debuginfoUpgrade softhsmUpgrade ipa-debuginfoUpgrade slapi-nis-debugsourceUpgrade ipa-client-epnUpgrade ipa-debugsourceUpgrade opendnssecUpgrade ipa-serverUpgrade opendnssec-debugsourceUpgrade ipa-server-trust-ad-debuginfoUpgrade bind-dyndb-ldapUpgrade slapi-nis-debuginfoUpgrade softhsm-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade ipa-client-sambaUpgrade bind-dyndb-ldap-debuginfoUpgrade softhsm-debugsourceUpgrade ipa-client-debuginfo | Jun 17, 2024 | Jun 12, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub