A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-ipatestsUpgrade ipa-commonUpgrade ipa-selinuxUpgrade ipa-client-sambaUpgrade python3-ipaserverUpgrade ipa-client-epnUpgrade python3-ipaclientUpgrade ipa-serverUpgrade ipa-clientUpgrade ipa-client-encrypted-dnsUpgrade python3-yubicoUpgrade bind-dyndb-ldapUpgrade ipa-healthcheckUpgrade custodiaUpgrade python3-jwcryptoUpgrade ipa-selinux-nfastUpgrade ipa-server-dnsUpgrade python3-qrcode-coreUpgrade ipa-healthcheck-coreUpgrade opendnssecUpgrade python3-ipalibUpgrade ipa-python-compatUpgrade python3-custodiaUpgrade softhsmUpgrade slapi-nisUpgrade ipa-client-commonUpgrade python3-pyusbUpgrade python3-kdcproxyUpgrade python3-qrcodeUpgrade ipa-selinux-lunaUpgrade ipa-server-commonUpgrade ipa-server-encrypted-dnsUpgrade softhsm-develUpgrade ipa-server-trust-ad | Jul 1, 2025 | Jun 17, 2025 |
| Amazon Linux Ami 2 | — | Upgrade python2-ipaserverUpgrade ipa-server-dnsUpgrade ipa-server-commonUpgrade python2-ipalibUpgrade ipa-debuginfoUpgrade python2-ipaclientUpgrade ipa-clientUpgrade ipa-serverUpgrade ipa-commonUpgrade ipa-server-trust-adUpgrade ipa-python-compatUpgrade ipa-client-common | Jun 25, 2025 | Jun 17, 2025 |
| Debian | — | Upgrade freeipa | Jun 20, 2025 | Jun 17, 2025 |
| Oracle_linux | — | Upgrade ipa-client-commonUpgrade opendnssecUpgrade custodiaUpgrade python3-ipaclientUpgrade ipa-commonUpgrade python3-ipaserverUpgrade python2-ipaserverUpgrade ipa-client-sambaUpgrade python3-qrcodeUpgrade python3-jwcryptoUpgrade python3-pyusbUpgrade python3-ipatestsUpgrade python3-ipalibUpgrade python3-qrcode-coreUpgrade bind-dyndb-ldapUpgrade softhsmUpgrade ipa-server-commonUpgrade ipa-server-encrypted-dnsUpgrade ipa-server-trust-adUpgrade ipa-clientUpgrade ipa-healthcheck-coreUpgrade ipa-selinux-lunaUpgrade python3-kdcproxyUpgrade ipa-python-compatUpgrade ipa-serverUpgrade python3-yubicoUpgrade ipa-client-encrypted-dnsUpgrade slapi-nisUpgrade ipa-selinux-nfastUpgrade ipa-server-dnsUpgrade ipa-client-epnUpgrade ipa-healthcheckUpgrade softhsm-develUpgrade ipa-selinuxUpgrade python3-custodiaUpgrade python2-ipalibUpgrade python2-ipaclient | Jun 30, 2025 | Jun 17, 2025 |
| Redhat_linux | — | No solution existsUpgrade ipa-client-commonUpgrade ipa-server-dnsUpgrade opendnssec-debugsourceUpgrade python2-ipalibUpgrade custodiaUpgrade python3-custodiaUpgrade python3-pyusbUpgrade softhsmUpgrade bind-dyndb-ldapUpgrade python3-ipalibUpgrade ipa-debuginfoUpgrade python3-kdcproxyUpgrade ipa-server-trust-adUpgrade ipa-server-debuginfoUpgrade ipa-server-commonUpgrade ipa-selinux-nfastUpgrade python3-qrcode-coreUpgrade softhsm-develUpgrade ipa-debugsourceUpgrade python3-qrcodeUpgrade ipa-python-compatUpgrade python2-ipaclientUpgrade ipa-healthcheck-coreUpgrade opendnssecUpgrade softhsm-debugsourceUpgrade ipa-server-encrypted-dnsUpgrade ipa-client-debuginfoUpgrade python3-ipatestsUpgrade ipa-server-trust-ad-debuginfoUpgrade slapi-nisUpgrade ipa-client-sambaUpgrade python3-jwcryptoUpgrade ipa-commonUpgrade bind-dyndb-ldap-debugsourceUpgrade ipa-serverUpgrade ipa-client-encrypted-dnsUpgrade ipa-clientUpgrade python3-ipaclientUpgrade ipa-healthcheckUpgrade softhsm-debuginfoUpgrade python2-ipaserverUpgrade opendnssec-debuginfoUpgrade slapi-nis-debuginfoUpgrade python3-yubicoUpgrade ipa-client-epnUpgrade bind-dyndb-ldap-debuginfoUpgrade ipa-selinuxUpgrade python3-ipaserverUpgrade slapi-nis-debugsourceUpgrade ipa-selinux-luna | Jun 18, 2025 | Jun 17, 2025 |
| Rocky_linux | — | Upgrade slapi-nisUpgrade ipa-server-trust-adUpgrade slapi-nis-debugsourceUpgrade ipa-debugsourceUpgrade ipa-server-debuginfoUpgrade opendnssec-debugsourceUpgrade softhsm-debugsourceUpgrade ipa-server-trust-ad-debuginfoUpgrade opendnssec-debuginfoUpgrade softhsm-debuginfoUpgrade ipa-client-epnUpgrade softhsmUpgrade softhsm-develUpgrade opendnssecUpgrade slapi-nis-debuginfoUpgrade ipa-clientUpgrade ipa-client-sambaUpgrade bind-dyndb-ldap-debugsourceUpgrade ipa-server-encrypted-dnsUpgrade bind-dyndb-ldapUpgrade ipa-client-encrypted-dnsUpgrade bind-dyndb-ldap-debuginfoUpgrade ipa-serverUpgrade ipa-debuginfoUpgrade ipa-client-debuginfo | Jul 31, 2025 | Jul 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub