A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal key directly. For user principals, this key is a hash of a public per-principal randomly-generated salt and the user’s password. If a principal is compromised it means the attacker would be able to retrieve tickets encrypted to any principal, all of them being encrypted by their own key directly. By taking these tickets and salts offline, the attacker could run brute force attacks to find character strings able to decrypt tickets when combined to a principal salt (i.e. find the principal’s password).
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-ipaserverUpgrade python3-ipalibUpgrade ipa-server-trust-adUpgrade custodiaUpgrade ipa-commonUpgrade ipa-server-commonUpgrade python3-ipatestsUpgrade ipa-healthcheckUpgrade bind-dyndb-ldapUpgrade python3-yubicoUpgrade ipa-selinuxUpgrade ipa-serverUpgrade softhsmUpgrade ipa-client-epnUpgrade ipa-healthcheck-coreUpgrade softhsm-develUpgrade ipa-client-commonUpgrade python3-jwcryptoUpgrade ipa-client-sambaUpgrade python3-custodiaUpgrade python3-ipaclientUpgrade python3-qrcodeUpgrade ipa-python-compatUpgrade python3-qrcode-coreUpgrade python3-kdcproxyUpgrade slapi-nisUpgrade ipa-server-dnsUpgrade ipa-clientUpgrade python3-pyusbUpgrade opendnssec | Jun 24, 2024 | Jun 12, 2024 |
| Amazon Linux Ami 2 | — | Upgrade ipa-server-dnsUpgrade ipa-python-compatUpgrade python2-ipalibUpgrade python2-ipaclientUpgrade ipa-serverUpgrade ipa-clientUpgrade ipa-debuginfoUpgrade ipa-commonUpgrade ipa-server-commonUpgrade ipa-client-commonUpgrade python2-ipaserverUpgrade ipa-server-trust-ad | Jul 12, 2024 | Jun 12, 2024 |
| Centos_linux | — | Upgrade python2-ipalibUpgrade ipa-commonUpgrade ipa-python-compatUpgrade ipa-serverUpgrade ipa-server-dnsUpgrade python2-ipaclientUpgrade ipa-server-trust-adUpgrade python2-ipaserverUpgrade ipa-clientUpgrade ipa-client-commonUpgrade ipa-server-commonUpgrade ipa-debuginfo | Jun 11, 2024 | Jun 10, 2024 |
| Debian | — | Upgrade freeipa | May 15, 2025 | Jun 12, 2024 |
| Oracle_linux | — | Upgrade python2-ipaclientUpgrade ipa-client-commonUpgrade ipa-commonUpgrade python3-custodiaUpgrade ipa-server-commonUpgrade ipa-server-dnsUpgrade python3-yubicoUpgrade bind-dyndb-ldapUpgrade softhsmUpgrade ipa-client-sambaUpgrade ipa-serverUpgrade ipa-python-compatUpgrade python2-ipalibUpgrade python3-ipaclientUpgrade python3-ipaserverUpgrade opendnssecUpgrade python3-jwcryptoUpgrade slapi-nisUpgrade python3-qrcode-coreUpgrade python3-ipalibUpgrade python3-pyusbUpgrade softhsm-develUpgrade ipa-clientUpgrade ipa-healthcheck-coreUpgrade ipa-healthcheckUpgrade ipa-selinuxUpgrade ipa-client-epnUpgrade python3-ipatestsUpgrade python2-ipaserverUpgrade ipa-server-trust-adUpgrade python3-kdcproxyUpgrade custodiaUpgrade python3-qrcode | Jul 22, 2024 | Jun 10, 2024 |
| Redhat_linux | — | Upgrade ipa-server-debuginfoUpgrade ipa-server-trust-adUpgrade ipa-client-commonUpgrade ipa-debuginfoUpgrade ipa-server-dnsUpgrade python3-ipalibUpgrade python2-ipalibUpgrade ipa-server-commonUpgrade ipa-client-debuginfoUpgrade ipa-debugsourceUpgrade ipa-python-compatUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-clientUpgrade python3-ipaclientUpgrade python2-ipaclientUpgrade ipa-serverUpgrade python2-ipaserverUpgrade python3-ipatestsUpgrade ipa-client-epnUpgrade python3-ipaserverUpgrade ipa-selinuxUpgrade ipa-client-sambaUpgrade ipa-common | Jun 11, 2024 | Jun 10, 2024 |
| Rocky_linux | — | Upgrade softhsmUpgrade softhsm-develUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-client-sambaUpgrade ipa-debuginfoUpgrade opendnssec-debugsourceUpgrade ipa-client-debuginfoUpgrade ipa-client-epnUpgrade opendnssecUpgrade bind-dyndb-ldapUpgrade bind-dyndb-ldap-debuginfoUpgrade ipa-clientUpgrade opendnssec-debuginfoUpgrade softhsm-debuginfoUpgrade slapi-nis-debugsourceUpgrade ipa-serverUpgrade ipa-server-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade softhsm-debugsourceUpgrade slapi-nisUpgrade ipa-server-trust-adUpgrade slapi-nis-debuginfoUpgrade ipa-debugsource | Jun 17, 2024 | Jun 12, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub