VYPR

IPA

by Red Hat

CVEs (7)

  • CVE-2019-14867HigNov 27, 2019
    risk 0.58cvss 8.8epss 0.07

    A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker…

  • CVE-2012-5631HigNov 25, 2019
    risk 0.57cvss 8.8epss 0.02

    ipa 3.0 does not properly check server identity before sending credential containing cookies

  • CVE-2017-2590HigJul 27, 2018
    risk 0.53cvss 8.1epss 0.01

    A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing…

  • CVE-2023-5455MedJan 10, 2024
    risk 0.42cvss 6.5epss 0.01

    A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system…

  • CVE-2019-10195MedNov 27, 2019
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch…

  • CVE-2020-1722MedApr 27, 2020
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat…

  • CVE-2019-14826MedSep 17, 2019
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.