Freeipa
Products
2- 38 CVEs
- 2 CVEs
Recent CVEs
38| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-5284 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2017 | ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable. | ||
| CVE-2025-7493 | Cri | 0.59 | 9.1 | 0.01 | Sep 30, 2025 | A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM… | ||
| CVE-2025-4404 | Cri | 0.59 | 9.1 | 0.02 | Jun 17, 2025 | A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM… | ||
| CVE-2019-14867 | Hig | 0.58 | 8.8 | 0.07 | Nov 27, 2019 | A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker… | ||
| CVE-2026-76578 | Cri | 0.57 | 9.8 | 0.01 | Sep 7, 2026 | A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory… | ||
| CVE-2012-5631 | Hig | 0.57 | 8.8 | 0.02 | Nov 25, 2019 | ipa 3.0 does not properly check server identity before sending credential containing cookies | ||
| CVE-2017-11191 | Hig | 0.57 | 8.8 | 0.02 | Sep 28, 2017 | FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not… | ||
| CVE-2026-11861 | Cri | 0.55 | 9.6 | 0.00 | Aug 20, 2026 | A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name… | ||
| CVE-2026-18147 | Hig | 0.53 | 8.1 | 0.00 | Sep 9, 2026 | A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could… | ||
| CVE-2024-3183 | Hig | 0.53 | 8.1 | 0.02 | Jun 12, 2024 | A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal… | ||
| CVE-2017-2590 | Hig | 0.53 | 8.1 | 0.01 | Jul 27, 2018 | A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing… | ||
| CVE-2026-13097 | Hig | 0.50 | 8.7 | 0.00 | Aug 20, 2026 | A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP… | ||
| CVE-2024-2698 | Hig | 0.50 | 8.8 | 0.01 | Jun 12, 2024 | A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed_to_delegate() function: If… | ||
| CVE-2017-12169 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2018 | It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potentially use this flaw to disclose the password hashes belonging to Stage Users. This security issue does… | ||
| CVE-2015-5179 | Hig | 0.49 | 7.5 | 0.01 | Sep 20, 2017 | FreeIPA might display user data improperly via vectors involving non-printable characters. | ||
| CVE-2016-7030 | Hig | 0.49 | 7.5 | 0.05 | Aug 28, 2017 | FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on. | ||
| CVE-2016-5414 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2017 | FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services. | ||
| CVE-2026-79678 | Hig | 0.46 | 8.1 | 0.01 | Sep 7, 2026 | A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege… | ||
| CVE-2026-19550 | Hig | 0.46 | 8.2 | 0.00 | Aug 11, 2026 | A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an… | ||
| CVE-2026-73198 | Hig | 0.42 | 7.5 | 0.00 | Aug 20, 2026 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded… |
- risk 0.64cvss 9.8epss 0.01
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
- risk 0.59cvss 9.1epss 0.01
A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM…
- risk 0.59cvss 9.1epss 0.02
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM…
- risk 0.58cvss 8.8epss 0.07
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker…
- risk 0.57cvss 9.8epss 0.01
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory…
- risk 0.57cvss 8.8epss 0.02
ipa 3.0 does not properly check server identity before sending credential containing cookies
- risk 0.57cvss 8.8epss 0.02
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not…
- risk 0.55cvss 9.6epss 0.00
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name…
- risk 0.53cvss 8.1epss 0.00
A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could…
- risk 0.53cvss 8.1epss 0.02
A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal…
- risk 0.53cvss 8.1epss 0.01
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing…
- risk 0.50cvss 8.7epss 0.00
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP…
- risk 0.50cvss 8.8epss 0.01
A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed_to_delegate() function: If…
- risk 0.49cvss 7.5epss 0.02
It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potentially use this flaw to disclose the password hashes belonging to Stage Users. This security issue does…
- risk 0.49cvss 7.5epss 0.01
FreeIPA might display user data improperly via vectors involving non-printable characters.
- risk 0.49cvss 7.5epss 0.05
FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.
- risk 0.49cvss 7.5epss 0.01
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
- risk 0.46cvss 8.1epss 0.01
A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege…
- risk 0.46cvss 8.2epss 0.00
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an…
- risk 0.42cvss 7.5epss 0.00
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded…