CVE-2008-3274
published 2008-09-12CVE-2008-3274: The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, which…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.84%
76.6th percentile
The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, which allows remote attackers to obtain the Kerberos master key via an anonymous LDAP query.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_ipa | — | — |
| redhat | freeipa | <= 1.1.0 | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
IPA Kerberos master password disclosure
vendor_redhat·2008-09-10·CVSS 5.0
CVE-2008-3274 [MEDIUM] IPA Kerberos master password disclosure
IPA Kerberos master password disclosure
The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, which allows remote attackers to obtain the Kerberos master key via an anonymous LDAP query.
GHSA
GHSA-8w34-c24h-wvp3: The default configuration of Red Hat Enterprise IPA 1
ghsa_unreviewed·2022-05-01
CVE-2008-3274 [MEDIUM] CWE-200 GHSA-8w34-c24h-wvp3: The default configuration of Red Hat Enterprise IPA 1
The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, which allows remote attackers to obtain the Kerberos master key via an anonymous LDAP query.
No detection rules found.
No public exploits indexed.
http://git.fedorahosted.org/git/freeipa.git/?p=freeipa.git%3Ba=commit%3Bh=9932887f2af38b9701efec27707648c026ec445chttp://rhn.redhat.com/errata/RHSA-2008-0860.htmlhttp://secunia.com/advisories/31861http://www.freeipa.org/page/CVE-2008-3274http://www.freeipa.org/page/Downloadshttp://www.freeipa.org/page/Newshttp://www.securityfocus.com/bid/31111http://www.securitytracker.com/id?1020850https://bugzilla.redhat.com/show_bug.cgi?id=457835https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00733.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg00743.htmlhttp://git.fedorahosted.org/git/freeipa.git/?p=freeipa.git%3Ba=commit%3Bh=9932887f2af38b9701efec27707648c026ec445chttp://rhn.redhat.com/errata/RHSA-2008-0860.htmlhttp://secunia.com/advisories/31861http://www.freeipa.org/page/CVE-2008-3274http://www.freeipa.org/page/Downloadshttp://www.freeipa.org/page/Newshttp://www.securityfocus.com/bid/31111http://www.securitytracker.com/id?1020850https://bugzilla.redhat.com/show_bug.cgi?id=457835https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00733.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg00743.html
2008-09-12
Published