CVE-2023-5455
published 2024-01-10CVE-2023-5455: A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.57%
43.4th percentile
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeipa | < freeipa 4.11.1-1 (forky) | freeipa 4.11.1-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freeipa | freeipa | < 4.6.10 | 4.6.10 |
| freeipa | freeipa | — | — |
| freeipa | freeipa | >= 0 < 4.11.1-1 | 4.11.1-1 |
| freeipa | freeipa | >= 0 < 4.11.1-1 | 4.11.1-1 |
| freeipa | freeipa | >= 4.10.0 < 4.10.3 | 4.10.3 |
| freeipa | freeipa | >= 4.7.0 < 4.9.14 | 4.9.14 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-5455: A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA
osv·2024-01-10·CVSS 6.5
CVE-2023-5455 [MEDIUM] CVE-2023-5455: A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
GHSA
GHSA-45hh-rj6v-548f: A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA
ghsa_unreviewed·2024-01-10
CVE-2023-5455 [MEDIUM] CWE-352 GHSA-45hh-rj6v-548f: A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
Red Hat
ipa: Invalid CSRF protection
vendor_redhat·2024-01-10·CVSS 6.5
CVE-2023-5455 [MEDIUM] CWE-352 ipa: Invalid CSRF protection
ipa: Invalid CSRF protection
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user int
Debian
CVE-2023-5455: freeipa - A Cross-site request forgery vulnerability exists in ipa/session/login_password ...
vendor_debian·2023·CVSS 6.5
CVE-2023-5455 [MEDIUM] CVE-2023-5455: freeipa - A Cross-site request forgery vulnerability exists in ipa/session/login_password ...
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
Scope: local
bookworm: open
forky: resolved (fixed in 4.11.1-1)
sid: resolved (fixed in 4.11.1-1)
trixie: resolved (fixed in 4.11.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:0137https://access.redhat.com/errata/RHSA-2024:0138https://access.redhat.com/errata/RHSA-2024:0139https://access.redhat.com/errata/RHSA-2024:0140https://access.redhat.com/errata/RHSA-2024:0141https://access.redhat.com/errata/RHSA-2024:0142https://access.redhat.com/errata/RHSA-2024:0143https://access.redhat.com/errata/RHSA-2024:0144https://access.redhat.com/errata/RHSA-2024:0145https://access.redhat.com/security/cve/CVE-2023-5455https://bugzilla.redhat.com/show_bug.cgi?id=2242828https://www.freeipa.org/release-notes/4-10-3.htmlhttps://www.freeipa.org/release-notes/4-11-1.htmlhttps://www.freeipa.org/release-notes/4-6-10.htmlhttps://www.freeipa.org/release-notes/4-9-14.htmlhttps://access.redhat.com/errata/RHSA-2024:0137https://access.redhat.com/errata/RHSA-2024:0138https://access.redhat.com/errata/RHSA-2024:0139https://access.redhat.com/errata/RHSA-2024:0140https://access.redhat.com/errata/RHSA-2024:0141https://access.redhat.com/errata/RHSA-2024:0142https://access.redhat.com/errata/RHSA-2024:0143https://access.redhat.com/errata/RHSA-2024:0144https://access.redhat.com/errata/RHSA-2024:0145https://access.redhat.com/errata/RHSA-2024:0252https://access.redhat.com/security/cve/CVE-2023-5455https://bugzilla.redhat.com/show_bug.cgi?id=2242828https://lists.fedoraproject.org/archives/list/[email protected]/message/U76DAZZVY7V4XQBOOV5ETPTHW3A6MW5O/https://lists.fedoraproject.org/archives/list/[email protected]/message/UFNUQH7IOHTKCTKQWFHONWGUBOUANL6I/https://www.freeipa.org/release-notes/4-10-3.htmlhttps://www.freeipa.org/release-notes/4-11-1.htmlhttps://www.freeipa.org/release-notes/4-6-10.htmlhttps://www.freeipa.org/release-notes/4-9-14.html
2024-01-10
Published