cbcvebase.
CVE-2023-5455
published 2024-01-10

CVE-2023-5455: A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the…

PriorityP335medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.57%
43.4th percentile
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

Affected

58 ranges· showing 25
VendorProductVersion rangeFixed in
debianfreeipa< freeipa 4.11.1-1 (forky)freeipa 4.11.1-1 (forky)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
freeipafreeipa< 4.6.104.6.10
freeipafreeipa
freeipafreeipa>= 0 < 4.11.1-14.11.1-1
freeipafreeipa>= 0 < 4.11.1-14.11.1-1
freeipafreeipa>= 4.10.0 < 4.10.34.10.3
freeipafreeipa>= 4.7.0 < 4.9.144.9.14
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_for_arm_64_eus
redhatenterprise_linux_for_arm_64_eus
redhatenterprise_linux_for_arm_64_eus
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.