CVE-2020-1722
published 2020-04-27CVE-2020-1722: A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing…
PriorityP424medium5.3CVSS 3.1
AVNACHPRNUIRSUCNINAH
EPSS
1.05%
60.6th percentile
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeipa | < freeipa 4.8.8-2 (bookworm) | freeipa 4.8.8-2 (bookworm) |
| freeipa | freeipa | >= 0 < 4.8.8-2 | 4.8.8-2 |
| freeipa | freeipa | >= 0 < 4.8.8-2 | 4.8.8-2 |
| freeipa | freeipa | >= 0 < 4.8.8-2 | 4.8.8-2 |
| freeipa | freeipa | 4.0.0 – 4.8.0 | — |
| red_hat | ipa | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ipa: No password length restriction leads to denial of service
vendor_redhat·2020-04-14·CVSS 5.3
CVE-2020-1722 [MEDIUM] CWE-400 ipa: No password length restriction leads to denial of service
ipa: No password length restriction leads to denial of service
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
A flaw was found in IPA. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
Package: ipa (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2020-1722: freeipa - A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very lo...
vendor_debian·2020·CVSS 5.3
CVE-2020-1722 [MEDIUM] CVE-2020-1722: freeipa - A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very lo...
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 4.8.8-2)
forky: resolved (fixed in 4.8.8-2)
sid: resolved (fixed in 4.8.8-2)
trixie: resolved (fixed in 4.8.8-2)
GHSA
GHSA-mvj3-pw74-8w47: A flaw was found in all ipa versions 4
ghsa_unreviewed·2022-05-24
CVE-2020-1722 [HIGH] CWE-400 GHSA-mvj3-pw74-8w47: A flaw was found in all ipa versions 4
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
OSV
CVE-2020-1722: A flaw was found in all ipa versions 4
osv·2020-04-27·CVSS 5.3
CVE-2020-1722 [MEDIUM] CVE-2020-1722: A flaw was found in all ipa versions 4
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
No detection rules found.
Nuclei
Jenkin Audit Trail <=3.2 - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2020-2140 [MEDIUM] Jenkin Audit Trail <=3.2 - Cross-Site Scripting
Jenkin Audit Trail =3.3) which includes a fix for this vulnerability.
reference:
- https://www.jenkins.io/security/advisory/2020-03-09/
- https://nvd.nist.gov/vuln/detail/CVE-2020-2140
- https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1722
- http://www.openwall.com/lists/oss-security/2020/03/09/1
- https://github.com/merlinepedra25/nuclei-templates
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score: 6.1
cve-id: CVE-2020-2140
cwe-id: CWE-79
epss-score: 0.44807
epss-percentile: 0.97574
cpe: cpe:2.3:a:jenkins:audit_trail:*:*:*:*:*:jenkins:*:*
metadata:
max-request: 2
vendor: jenkins
product: audit_trail
framework: jenkins
tags: cve,cve2020,jenkins,xss,plugin,vuln
http:
- method: GET
path:
- "{{BaseURL}}/descriptorByName/AuditTrailPlugin/regexCheck
Bugzilla
CVE-2020-1722 freeipa: ipa: No password length restriction leads to denial of service [fedora-all]
bugzilla·2020-04-14·CVSS 5.3
CVE-2020-1722 [MEDIUM] CVE-2020-1722 freeipa: ipa: No password length restriction leads to denial of service [fedora-all]
CVE-2020-1722 freeipa: ipa: No password length restriction leads to denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2020-1722 ipa: No password length restriction leads to denial of service
bugzilla·2020-01-20·CVSS 5.3
CVE-2020-1722 [MEDIUM] CVE-2020-1722 ipa: No password length restriction leads to denial of service
CVE-2020-1722 ipa: No password length restriction leads to denial of service
A vulnerability was found in IPA, where by sending a very long password (1.000.000 characters) it's possible to cause a denial a service attack on the server. This may lead to the website becoming unavailable or unresponsive. Usually, this problem is caused by a vulnerable password hashing implementation. When a long password is sent, the password hashing process will result in CPU and memory exhaustion.
Discussion:
Acknowledgments:
Name: Pritam Singh (Red Hat)
---
Created freeipa tracking bugs for this issue:
Affects: fedora-all [bug 1823621]
---
Link FreeIPA issue 8268 here: https://pagure.io/freeipa/issue/8268
FreeIPA team agrees with Red Hat Security Response Team assessment that this is a low severi
2020-04-27
Published