VYPR
Vendor

Freeipa

Products
2
CVEs
38
Across products
40
Status
Private

Products

2

Recent CVEs

38
View all 38 CVEs →
  • CVE-2015-5284CriSep 21, 2017
    risk 0.64cvss 9.8epss 0.01

    ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.

  • CVE-2025-7493CriSep 30, 2025
    risk 0.59cvss 9.1epss 0.01

    A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM…

  • CVE-2025-4404CriJun 17, 2025
    risk 0.59cvss 9.1epss 0.02

    A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM…

  • CVE-2019-14867HigNov 27, 2019
    risk 0.58cvss 8.8epss 0.07

    A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker…

  • CVE-2026-76578CriSep 7, 2026
    risk 0.57cvss 9.8epss 0.01

    A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory…

  • CVE-2012-5631HigNov 25, 2019
    risk 0.57cvss 8.8epss 0.02

    ipa 3.0 does not properly check server identity before sending credential containing cookies

  • CVE-2017-11191HigSep 28, 2017
    risk 0.57cvss 8.8epss 0.02

    FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not…

  • CVE-2026-11861CriAug 20, 2026
    risk 0.55cvss 9.6epss 0.00

    A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name…

  • CVE-2026-18147HigSep 9, 2026
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could…

  • CVE-2024-3183HigJun 12, 2024
    risk 0.53cvss 8.1epss 0.02

    A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal…

  • CVE-2017-2590HigJul 27, 2018
    risk 0.53cvss 8.1epss 0.01

    A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing…

  • CVE-2026-13097HigAug 20, 2026
    risk 0.50cvss 8.7epss 0.00

    A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP…

  • CVE-2024-2698HigJun 12, 2024
    risk 0.50cvss 8.8epss 0.01

    A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed_to_delegate() function: If…

  • CVE-2017-12169HigJan 10, 2018
    risk 0.49cvss 7.5epss 0.02

    It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potentially use this flaw to disclose the password hashes belonging to Stage Users. This security issue does…

  • CVE-2015-5179HigSep 20, 2017
    risk 0.49cvss 7.5epss 0.01

    FreeIPA might display user data improperly via vectors involving non-printable characters.

  • CVE-2016-7030HigAug 28, 2017
    risk 0.49cvss 7.5epss 0.05

    FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.

  • CVE-2016-5414HigJun 27, 2017
    risk 0.49cvss 7.5epss 0.01

    FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.

  • CVE-2026-79678HigSep 7, 2026
    risk 0.46cvss 8.1epss 0.01

    A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege…

  • CVE-2026-19550HigAug 11, 2026
    risk 0.46cvss 8.2epss 0.00

    A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an…

  • CVE-2026-73198HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded…