Medium severity6.5NVD Advisory· Published Jan 10, 2024· Updated Jun 17, 2026
CVE-2023-5455
CVE-2023-5455
Description
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
100cpe:/a:redhat:enterprise_linux:8::appstream+ 11 more
- cpe:/a:redhat:enterprise_linux:8::appstreamrange: 8090020231201152514.3387e3d0
- cpe:/a:redhat:enterprise_linux:9::crbrange: 0:4.10.2-5.el9_3
- cpe:/o:redhat:enterprise_linux:6
- cpe:/o:redhat:enterprise_linux:8
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:arm64:*
- cpe:2.3:o:redhat:enterprise_linux:8.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:9.0:*:*:*:*:*:arm64:*
- cpe:2.3:o:redhat:enterprise_linux_server:9.2:*:*:*:*:*:arm64:*
- cpe:/o:redhat:enterprise_linux:7::serverrange: 0:4.6.8-5.el7_9.16
- Red Hat/Red Hat Enterprise Linux 8.6 Extended Update Supportv5cpe:/a:redhat:rhel_eus:8.6::appstreamRange: 8060020231208020207.ada582f1
- Red Hat/Red Hat Enterprise Linux 8.8 Extended Update Supportv5cpe:/a:redhat:rhel_eus:8.8::appstreamRange: 8080020231201153604.b0a6ceea
- Red Hat/Red Hat Enterprise Linux 9.0 Extended Update Supportv5cpe:/a:redhat:rhel_eus:9.0::appstreamRange: 0:4.9.8-9.el9_0
- Red Hat/Red Hat Enterprise Linux 9.2 Extended Update Supportv5cpe:/a:redhat:rhel_eus:9.2::appstreamRange: 0:4.10.1-10.el9_2
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:codeready_linux_builder:-:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:arm64:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.8:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.8:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.8:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.8:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:9.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_for_ibm_z_systems:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:*
- cpe:/a:redhat:rhel_aus:8.2::appstreamrange: 8020020231123154806.792f4060
- cpe:/a:redhat:rhel_aus:8.4::appstreamrange: 8040020231123154610.5b01ab7e
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- osv-coords30 versionspkg:rpm/almalinux/ipa-selinuxpkg:rpm/almalinux/ipa-serverpkg:rpm/almalinux/ipa-server-commonpkg:rpm/almalinux/ipa-server-dnspkg:rpm/almalinux/ipa-clientpkg:rpm/almalinux/ipa-client-commonpkg:rpm/almalinux/ipa-client-epnpkg:rpm/almalinux/ipa-client-sambapkg:rpm/almalinux/ipa-commonpkg:rpm/almalinux/ipa-server-trust-adpkg:rpm/almalinux/python3-ipaclientpkg:rpm/almalinux/python3-ipalibpkg:rpm/almalinux/python3-ipaserverpkg:rpm/almalinux/python3-ipatestspkg:rpm/almalinux/bind-dyndb-ldappkg:rpm/almalinux/custodiapkg:rpm/almalinux/ipa-healthcheckpkg:rpm/almalinux/ipa-healthcheck-corepkg:rpm/almalinux/ipa-python-compatpkg:rpm/almalinux/opendnssecpkg:rpm/almalinux/python3-custodiapkg:rpm/almalinux/python3-jwcryptopkg:rpm/almalinux/python3-kdcproxypkg:rpm/almalinux/python3-pyusbpkg:rpm/almalinux/python3-qrcodepkg:rpm/almalinux/python3-qrcode-corepkg:rpm/almalinux/python3-yubicopkg:rpm/almalinux/slapi-nispkg:rpm/almalinux/softhsmpkg:rpm/almalinux/softhsm-devel
< 4.10.2-5.el9_3.alma.1+ 29 more
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 4.10.2-5.el9_3.alma.1
- (no CPE)range: < 11.6-4.module_el8.6.0+3339+9b5fdd22
- (no CPE)range: < 0.6.0-3.module_el8.6.0+2881+2f24dc92
- (no CPE)range: < 0.12-3.module_el8.9.0+3651+d05ea4c5
- (no CPE)range: < 0.12-3.module_el8.9.0+3651+d05ea4c5
- (no CPE)range: < 4.9.12-11.module_el8.9.0+3715+e4197dc9.alma.1
- (no CPE)range: < 2.1.7-1.module_el8.6.0+2881+2f24dc92
- (no CPE)range: < 0.6.0-3.module_el8.6.0+2881+2f24dc92
- (no CPE)range: < 0.5.0-1.1.module_el8.7.0+3349+cfeff52e
- (no CPE)range: < 0.4-5.module_el8.9.0+3682+f63caf3e
- (no CPE)range: < 1.0.0-9.1.module_el8.7.0+3349+cfeff52e
- (no CPE)range: < 5.1-12.module_el8.6.0+2881+2f24dc92
- (no CPE)range: < 5.1-12.module_el8.6.0+2881+2f24dc92
- (no CPE)range: < 1.3.2-9.1.module_el8.7.0+3349+cfeff52e
- (no CPE)range: < 0.60.0-4.module_el8.9.0+3682+f63caf3e.alma.1
- (no CPE)range: < 2.6.0-5.module_el8.6.0+2881+2f24dc92
- (no CPE)range: < 2.6.0-5.module_el8.6.0+2881+2f24dc92
Patches
Vulnerability mechanics
References
18- access.redhat.com/errata/RHSA-2024:0137nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2024:0138nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2024:0139nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2024:0140nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2024:0141nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2024:0142nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2024:0143nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2024:0144nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2024:0145nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2024:0252nvdThird Party Advisory
- access.redhat.com/security/cve/CVE-2023-5455nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- www.freeipa.org/release-notes/4-10-3.htmlnvdRelease Notes
- www.freeipa.org/release-notes/4-11-1.htmlnvdRelease Notes
- www.freeipa.org/release-notes/4-6-10.htmlnvdRelease Notes
- www.freeipa.org/release-notes/4-9-14.htmlnvdRelease Notes
- lists.fedoraproject.org/archives/list/[email protected]/message/U76DAZZVY7V4XQBOOV5ETPTHW3A6MW5O/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/UFNUQH7IOHTKCTKQWFHONWGUBOUANL6I/nvd
News mentions
0No linked articles in our index yet.