cbcvebase.

Debian Freeipa vulnerabilities

14 known vulnerabilities affecting debian/freeipa.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM6LOW6

Vulnerabilities

Page 1 of 1
CVE-2019-14867P3HIGHCVSS 8.8fixed in freeipa 4.8.3-1 (bookworm)2019
CVE-2019-14867 [HIGH] CVE-2019-14867: freeipa - A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions bef... A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or
debian
CVE-2025-4404P3LOWCVSS 9.1fixed in freeipa 4.12.4-1 (forky)2025
CVE-2025-4404 [CRITICAL] CVE-2025-4404: freeipa - A privilege escalation from host to domain vulnerability was found in the FreeIP... A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in th
debian
CVE-2024-2698P3LOWCVSS 8.8fixed in freeipa 4.12.2-1 (forky)2024
CVE-2024-2698 [HIGH] CVE-2024-2698: freeipa - A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU... A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed_to_delegate() function: If the target service argument is NULL, then it means the KDC is probing for general constraine
debian
CVE-2024-3183P3LOWCVSS 8.1fixed in freeipa 4.12.2-1 (forky)2024
CVE-2024-3183 [HIGH] CVE-2024-3183: freeipa - A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypt... A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal key directly. For user principals, this key is a hash of a public per-principal randomly-genera
debian
CVE-2016-7030P3HIGHCVSS 7.5fixed in freeipa 4.4.4-1 (bookworm)2016
CVE-2016-7030 [HIGH] CVE-2016-7030: freeipa - FreeIPA uses a default password policy that locks an account after 5 unsuccessfu... FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on. Scope: local bookworm: resolved (fixed in 4.4.4-1) forky: resolved (fixed in 4.4.4-1) sid: resolved (fixed in 4.4.4-1) trixie: resolved (fixed i
debian
CVE-2019-10195P3MEDIUMCVSS 6.5fixed in freeipa 4.8.3-1 (bookworm)2019
CVE-2019-10195 [MEDIUM] CVE-2019-10195: freeipa - A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions bef... A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in Fre
debian
CVE-2016-5404P3MEDIUMCVSS 6.5fixed in freeipa 4.3.2-5 (bookworm)2016
CVE-2016-5404 [MEDIUM] CVE-2016-5404: freeipa - The cert_revoke command in FreeIPA does not check for the "revoke certificate" p... The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission. Scope: local bookworm: resolved (fixed in 4.3.2-5) forky: resolved (fixed in 4.3.2-5) sid: resolved (fixed in 4.3.2-5) trixie: resolved (fixed in 4.3.2
debian
CVE-2023-5455P3LOWCVSS 6.5fixed in freeipa 4.11.1-1 (forky)2023
CVE-2023-5455 [MEDIUM] CVE-2023-5455: freeipa - A Cross-site request forgery vulnerability exists in ipa/session/login_password ... A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-poin
debian
CVE-2016-9575P4MEDIUMCVSS 6.3fixed in freeipa 4.4.4-1 (bookworm)2016
CVE-2016-9575 [MEDIUM] CVE-2016-9575: freeipa - Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly c... Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates fo
debian
CVE-2014-7828P4LOWCVSS 3.5fixed in freeipa 4.0.5-1 (bookworm)2014
CVE-2014-7828 [LOW] CVE-2014-7828: freeipa - FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows r... FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind. Scope: local bookworm: resolved (fixed in 4.0.5-1) forky: resolved (fixed in 4.0.5-1) sid: resolved (fixed in 4.0.5-1) trixie: resolved (fix
debian
CVE-2024-11029P4MEDIUMCVSS 5.5fixed in freeipa 4.12.4-1 (forky)2024
CVE-2024-11029 [MEDIUM] CVE-2024-11029: freeipa - A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA comm... A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with acc
debian
CVE-2024-1481P4MEDIUMCVSS 5.3fixed in freeipa 4.12.2-1 (forky)2024
CVE-2024-1481 [MEDIUM] CVE-2024-1481: freeipa - A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a H... A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service. Scope: local bookworm: open forky: resolved (fixed in 4.12.2-1) sid: resolved (fixed in 4.12.2-1) trixie: resolved (fixed in 4.12.2-1)
debian
CVE-2020-1722P4MEDIUMCVSS 5.3fixed in freeipa 4.8.8-2 (bookworm)2020
CVE-2020-1722 [MEDIUM] CVE-2020-1722: freeipa - A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very lo... A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixe
debian
CVE-2014-7850P4LOWCVSS 4.3fixed in freeipa 4.3.1-1 (bookworm)2014
CVE-2014-7850 [MEDIUM] CVE-2014-7850: freeipa - Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1... Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation. Scope: local bookworm: resolved (fixed in 4.3.1-1) forky: resolved (fixed in 4.3.1-1) sid: resolved (fixed in 4.3.1-1) trixie: resolved (fixed in 4.3.1-1)
debian
Debian Freeipa vulnerabilities | cvebase