Freeipa
Sign in to watchby Freeipa
CVEs (6)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2015-5284 | Cri | 0.64 | 9.8 | 0.00 | Sep 21, 2017 | ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable. | |
| CVE-2015-5179 | Hig | 0.49 | 7.5 | 0.00 | Sep 20, 2017 | FreeIPA might display user data improperly via vectors involving non-printable characters. | |
| CVE-2016-5414 | Hig | 0.49 | 7.5 | 0.00 | Jun 27, 2017 | FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services. | |
| CVE-2016-5404 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2016 | The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission. | |
| CVE-2014-7850 | 0.00 | — | 0.00 | Nov 28, 2014 | Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation. | ||
| CVE-2014-7828 | 0.00 | — | 0.00 | Nov 19, 2014 | FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind. |