A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade bind-dyndb-ldapUpgrade ipa-serverUpgrade ipa-clientUpgrade ipa-commonUpgrade python3-yubicoUpgrade ipa-healthcheckUpgrade ipa-client-epnUpgrade ipa-client-sambaUpgrade python3-ipaclientUpgrade python3-ipaserverUpgrade ipa-selinuxUpgrade ipa-client-encrypted-dnsUpgrade custodiaUpgrade python3-ipatestsUpgrade python3-jwcryptoUpgrade ipa-python-compatUpgrade python3-custodiaUpgrade python3-qrcodeUpgrade python3-pyusbUpgrade python3-kdcproxyUpgrade ipa-server-commonUpgrade ipa-healthcheck-coreUpgrade slapi-nisUpgrade ipa-server-trust-adUpgrade python3-qrcode-coreUpgrade ipa-server-encrypted-dnsUpgrade ipa-selinux-lunaUpgrade softhsmUpgrade ipa-client-commonUpgrade opendnssecUpgrade python3-ipalibUpgrade ipa-selinux-nfastUpgrade ipa-server-dnsUpgrade softhsm-devel | Jul 1, 2025 | Jun 17, 2025 |
| Amazon Linux Ami 2 | — | Upgrade ipa-python-compatUpgrade ipa-commonUpgrade python2-ipaclientUpgrade ipa-serverUpgrade ipa-clientUpgrade ipa-client-commonUpgrade ipa-debuginfoUpgrade ipa-server-trust-adUpgrade python2-ipalibUpgrade ipa-server-dnsUpgrade ipa-server-commonUpgrade python2-ipaserver | Jun 25, 2025 | Jun 17, 2025 |
| Debian | — | No solution existsUpgrade freeipa | Jun 20, 2025 | Jun 17, 2025 |
| Oracle_linux | — | Upgrade bind-dyndb-ldapUpgrade custodiaUpgrade ipa-server-commonUpgrade python3-qrcode-coreUpgrade softhsmUpgrade ipa-server-encrypted-dnsUpgrade python3-ipatestsUpgrade python3-pyusbUpgrade ipa-commonUpgrade python3-ipalibUpgrade opendnssecUpgrade ipa-client-commonUpgrade python3-jwcryptoUpgrade python3-ipaclientUpgrade python3-qrcodeUpgrade python3-ipaserverUpgrade python2-ipaserverUpgrade ipa-client-sambaUpgrade ipa-healthcheck-coreUpgrade python3-yubicoUpgrade python2-ipalibUpgrade python3-custodiaUpgrade slapi-nisUpgrade ipa-python-compatUpgrade python3-kdcproxyUpgrade ipa-clientUpgrade ipa-selinux-lunaUpgrade softhsm-develUpgrade ipa-server-dnsUpgrade ipa-selinux-nfastUpgrade ipa-serverUpgrade python2-ipaclientUpgrade ipa-healthcheckUpgrade ipa-server-trust-adUpgrade ipa-client-encrypted-dnsUpgrade ipa-selinuxUpgrade ipa-client-epn | Jun 30, 2025 | Jun 17, 2025 |
| Redhat_linux | — | Upgrade bind-dyndb-ldap-debuginfoUpgrade ipa-serverUpgrade ipa-client-epnUpgrade python3-ipaserverUpgrade python3-yubicoUpgrade ipa-clientUpgrade slapi-nis-debuginfoUpgrade python3-jwcryptoUpgrade python3-ipaclientUpgrade ipa-healthcheckUpgrade ipa-client-encrypted-dnsUpgrade softhsm-debuginfoUpgrade ipa-selinux-lunaUpgrade ipa-client-sambaUpgrade ipa-commonUpgrade opendnssec-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade ipa-selinuxUpgrade python2-ipaserverUpgrade slapi-nis-debugsourceUpgrade ipa-server-trust-ad-debuginfoUpgrade python3-ipatestsUpgrade slapi-nisUpgrade python3-custodiaUpgrade python2-ipalibUpgrade opendnssec-debugsourceUpgrade ipa-debuginfoNo solution existsUpgrade ipa-server-dnsUpgrade ipa-client-debuginfoUpgrade softhsm-develUpgrade softhsm-debugsourceUpgrade python2-ipaclientUpgrade ipa-server-encrypted-dnsUpgrade python3-qrcodeUpgrade ipa-debugsourceUpgrade bind-dyndb-ldapUpgrade ipa-server-debuginfoUpgrade ipa-selinux-nfastUpgrade ipa-server-commonUpgrade ipa-client-commonUpgrade opendnssecUpgrade ipa-healthcheck-coreUpgrade python3-pyusbUpgrade ipa-python-compatUpgrade custodiaUpgrade python3-ipalibUpgrade python3-kdcproxyUpgrade python3-qrcode-coreUpgrade softhsmUpgrade ipa-server-trust-ad | Jun 18, 2025 | Jun 17, 2025 |
| Rocky_linux | — | Upgrade slapi-nisUpgrade softhsm-debugsourceUpgrade opendnssec-debugsourceUpgrade opendnssec-debuginfoUpgrade ipa-server-debuginfoUpgrade ipa-server-trust-adUpgrade slapi-nis-debugsourceUpgrade softhsm-debuginfoUpgrade ipa-debugsourceUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-client-sambaUpgrade softhsmUpgrade softhsm-develUpgrade bind-dyndb-ldap-debuginfoUpgrade ipa-debuginfoUpgrade ipa-clientUpgrade bind-dyndb-ldap-debugsourceUpgrade slapi-nis-debuginfoUpgrade ipa-client-debuginfoUpgrade ipa-client-encrypted-dnsUpgrade ipa-server-encrypted-dnsUpgrade opendnssecUpgrade ipa-serverUpgrade bind-dyndb-ldapUpgrade ipa-client-epn | Jul 31, 2025 | Jul 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub