A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed_to_delegate() function: If the target service argument is NULL, then it means the KDC is probing for general constrained delegation rules and not checking a specific S4U2Proxy request. In FreeIPA 4.11.0, the behavior of ipadb_match_acl() was modified to match the changes from upstream MIT Kerberos 1.20. However, a mistake resulting in this mechanism applies in cases where the target service argument is set AND where it is unset. This results in S4U2Proxy requests being accepted regardless of whether or not there is a matching service delegation rule.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-pyusbUpgrade custodiaUpgrade python3-qrcode-coreUpgrade ipa-python-compatUpgrade softhsmUpgrade python3-custodiaUpgrade bind-dyndb-ldapUpgrade python3-qrcodeUpgrade ipa-server-dnsUpgrade ipa-server-commonUpgrade python3-ipalibUpgrade opendnssecUpgrade ipa-healthcheck-coreUpgrade softhsm-develUpgrade ipa-client-commonUpgrade ipa-server-trust-adUpgrade ipa-clientUpgrade python3-kdcproxyUpgrade python3-jwcryptoUpgrade ipa-serverUpgrade ipa-selinuxUpgrade python3-yubicoUpgrade slapi-nisUpgrade ipa-healthcheckUpgrade python3-ipaserverUpgrade ipa-client-sambaUpgrade python3-ipatestsUpgrade python3-ipaclientUpgrade ipa-commonUpgrade ipa-client-epn | Jun 24, 2024 | Jun 12, 2024 |
| Debian | — | No solution existsUpgrade freeipa | May 15, 2025 | Jun 12, 2024 |
| Oracle_linux | — | Upgrade ipa-server-commonUpgrade opendnssecUpgrade python3-yubicoUpgrade custodiaUpgrade python3-qrcode-coreUpgrade ipa-healthcheckUpgrade python3-jwcryptoUpgrade python3-ipatestsUpgrade ipa-server-trust-adUpgrade python3-ipalibUpgrade python3-ipaserverUpgrade python3-custodiaUpgrade ipa-clientUpgrade slapi-nisUpgrade ipa-client-sambaUpgrade softhsm-develUpgrade ipa-commonUpgrade ipa-selinuxUpgrade ipa-python-compatUpgrade ipa-serverUpgrade ipa-healthcheck-coreUpgrade python3-kdcproxyUpgrade softhsmUpgrade python3-qrcodeUpgrade ipa-server-dnsUpgrade python3-ipaclientUpgrade bind-dyndb-ldapUpgrade python3-pyusbUpgrade ipa-client-commonUpgrade ipa-client-epn | Jul 22, 2024 | Jun 10, 2024 |
| Redhat_linux | — | Upgrade ipa-server-trust-ad-debuginfoUpgrade ipa-client-sambaUpgrade ipa-server-trust-adUpgrade python3-ipatestsUpgrade ipa-server-commonUpgrade ipa-debugsourceUpgrade python3-ipalibUpgrade python3-ipaclientUpgrade ipa-selinuxUpgrade ipa-debuginfoUpgrade ipa-serverUpgrade ipa-clientUpgrade ipa-client-debuginfoUpgrade ipa-client-commonUpgrade ipa-server-debuginfoUpgrade ipa-commonUpgrade python3-ipaserverUpgrade ipa-server-dnsUpgrade ipa-client-epnNo solution exists | Jun 20, 2024 | Jun 12, 2024 |
| Rocky_linux | — | Upgrade softhsm-debuginfoUpgrade ipa-client-sambaUpgrade ipa-server-trust-ad-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade bind-dyndb-ldap-debuginfoUpgrade ipa-client-debuginfoUpgrade softhsm-debugsourceUpgrade bind-dyndb-ldapUpgrade opendnssec-debugsourceUpgrade slapi-nis-debuginfoUpgrade slapi-nis-debugsourceUpgrade ipa-debuginfoUpgrade ipa-server-trust-adUpgrade ipa-client-epnUpgrade softhsm-develUpgrade opendnssec-debuginfoUpgrade ipa-clientUpgrade slapi-nisUpgrade opendnssecUpgrade softhsmUpgrade ipa-serverUpgrade ipa-debugsourceUpgrade ipa-server-debuginfo | Jun 17, 2024 | Jun 12, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub