cbcvebase.
CVE-2020-1722
published 2020-04-27

CVE-2020-1722: A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing…

PriorityP424medium5.3CVSS 3.1
AVNACHPRNUIRSUCNINAH
EPSS
1.05%
60.6th percentile
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianfreeipa< freeipa 4.8.8-2 (bookworm)freeipa 4.8.8-2 (bookworm)
freeipafreeipa>= 0 < 4.8.8-24.8.8-2
freeipafreeipa>= 0 < 4.8.8-24.8.8-2
freeipafreeipa>= 0 < 4.8.8-24.8.8-2
freeipafreeipa4.0.0 – 4.8.0
red_hatipa
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.