VYPR

rpm package

almalinux/ipa-selinux-nfast

pkg:rpm/almalinux/ipa-selinux-nfast

Vulnerabilities (11)

  • CVE-2026-18147HigSep 9, 2026
    affected < 4.13.4-1.el9_8fixed 4.13.4-1.el9_8

    A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inj

  • CVE-2026-79678HigSep 7, 2026
    affected < 4.13.4-1.el9_8fixed 4.13.4-1.el9_8

    A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege lev

  • CVE-2026-76578CriSep 7, 2026
    affected < 4.13.4-1.el9_8fixed 4.13.4-1.el9_8

    A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory ser

  • CVE-2026-73198HigAug 20, 2026
    affected < 4.13.4-1.el9_8fixed 4.13.4-1.el9_8

    A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsive

  • CVE-2026-73197HigAug 20, 2026
    affected < 4.13.4-1.el9_8fixed 4.13.4-1.el9_8

    A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory,

  • CVE-2026-13097HigAug 20, 2026
    affected < 4.13.4-1.el9_8fixed 4.13.4-1.el9_8

    A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP writ

  • CVE-2026-11861CriAug 20, 2026
    affected < 4.13.4-1.el9_8fixed 4.13.4-1.el9_8

    A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name

  • CVE-2026-19550HigAug 11, 2026
    affected < 4.13.4-1.el9_8fixed 4.13.4-1.el9_8

    A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an at

  • CVE-2025-7493CriSep 30, 2025
    affected < 4.12.2-14.el9_6.5fixed 4.12.2-14.el9_6.5

    A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM crede

  • CVE-2025-4404CriJun 17, 2025
    affected < 4.12.2-14.el9_6.1fixed 4.12.2-14.el9_6.1

    A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM

  • CVE-2024-11029MedJan 15, 2025
    affected < 4.12.2-1.el9_5.3fixed 4.12.2-1.el9_5.3

    A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal data