FreeIPA kayıtları
freeipa üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %68
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-863 Incorrect Authorization3
- CWE-284 Improper Access Control2
- CWE-266 Incorrect Privilege Assignment1
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2015-5284İstismar yok | ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readfreeipa · freeipa · CWE-200 | Kritik9,8 | — | %1,0 | 21 Eyl 2017 |
37İzleyin | CVE-2019-14867İstismar yok | A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way thfreeipa · freeipa · CWE-94 | Yüksek8,8 | — | %7,4 | 27 Kas 2019 |
36İzleyin | CVE-2012-5631İstismar yok | ipa 3.0 does not properly check server identity before sending credential containing cookiesfreeipa · freeipa · CWE-565 | Yüksek8,8 | — | %1,8 | 25 Kas 2019 |
36İzleyin | CVE-2017-11191İstismar yok | FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action freeipa · freeipa · CWE-384 | Yüksek8,8 | — | %1,7 | 27 Eyl 2017 |
35İzleyin | CVE-2024-2698İstismar yok | Freeipa: delegation rules allow a proxy service to impersonate any user to access another target servicefreeipa · freeipa · CWE-863 | Yüksek8,8 | — | %0,7 | 12 Haz 2024 |
34İzleyin | CVE-2026-13097İstismar yok | Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastorefreeipa · freeipa · CWE-706 | Yüksek8,7 | — | %0,4 | 20 Ağu 2026 |
32İzleyin | CVE-2017-2590İstismar yok | A vulnerability was found in ipa before 4.4.freeipa · freeipa · CWE-732 | Yüksek8,1 | — | %1,3 | 27 Tem 2018 |
32İzleyin | CVE-2026-19550İstismar yok | Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writesfreeipa · freeipa · CWE-863 | Yüksek8,2 | — | %0,3 | 11 Ağu 2026 |
32İzleyin | CVE-2026-11861İstismar yok | Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationshipsfreeipa · freeipa · CWE-266 | Yüksek8,1 | — | %0,2 | 20 Ağu 2026 |
31İzleyin | CVE-2016-7030İstismar yok | FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to freeipa · freeipa · CWE-255 | Yüksek7,5 | — | %4,7 | 28 Ağu 2017 |
31İzleyin | CVE-2017-12169İstismar yok | It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission.freeipa · freeipa · CWE-200 | Yüksek7,5 | — | %1,9 | 10 Oca 2018 |
30İzleyin | CVE-2015-5179İstismar yok | FreeIPA might display user data improperly via vectors involving non-printable characters.freeipa · freeipa · CWE-20 | Yüksek7,5 | — | %1,1 | 20 Eyl 2017 |
30İzleyin | CVE-2016-5414İstismar yok | FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.freeipa · freeipa · CWE-284 | Yüksek7,5 | — | %1,0 | 27 Haz 2017 |
30İzleyin | CVE-2026-73198İstismar yok | Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body readfreeipa · freeipa · CWE-770 | Yüksek7,5 | — | %0,4 | 20 Ağu 2026 |
30İzleyin | CVE-2026-73197İstismar yok | Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body readfreeipa · freeipa · CWE-770 | Yüksek7,5 | — | %0,4 | 20 Ağu 2026 |
27İzleyin | CVE-2016-5404İstismar yok | The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revokefreeipa · freeipa · CWE-284 | Orta6,5 | — | %2,6 | 7 Eyl 2016 |
27İzleyin | CVE-2019-10195İstismar yok | A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way thfreeipa · freeipa · CWE-200 | Orta6,5 | — | %1,8 | 27 Kas 2019 |
26İzleyin | CVE-2023-5455İstismar yok | Ipa: invalid csrf protectionfreeipa · freeipa · CWE-352 | Orta6,5 | — | %0,6 | 10 Oca 2024 |
26İzleyin | CVE-2026-73196İstismar yok | Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encodingfreeipa · freeipa · CWE-770 | Orta6,5 | — | %0,4 | 20 Ağu 2026 |
25İzleyin | CVE-2016-9575İstismar yok | Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate proffreeipa · freeipa · CWE-863 | Orta6,3 | — | %0,7 | 13 Mar 2018 |
21İzleyin | CVE-2015-1827İstismar yok | The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accoufreeipa · freeipa · CWE-19 | Orta5,0 | — | %2,6 | 30 Mar 2015 |
21İzleyin | CVE-2020-1722İstismar yok | A flaw was found in all ipa versions 4.x.x through 4.8.0.freeipa · freeipa · CWE-400 | Orta5,3 | — | %1,2 | 27 Nis 2020 |
18İzleyin | CVE-2014-7850İstismar yok | Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script orfreeipa · freeipa · CWE-79 | Orta4,3 | — | %1,9 | 28 Kas 2014 |
17İzleyin | CVE-2019-14826İstismar yok | A flaw was found in FreeIPA versions 4.5.0 and later.freeipa · freeipa · CWE-613 | Orta4,4 | — | %0,3 | 17 Eyl 2019 |
15İzleyin | CVE-2014-7828İstismar yok | FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the twfreeipa · freeipa · CWE-264 | Düşük3,5 | — | %2,1 | 19 Kas 2014 |
- CVE-2015-528439İzleyin
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world read
KritikCVSS 9,8İstismar yokEPSS %1freeipa · freeipa21 Eyl 2017
- CVE-2019-1486737İzleyin
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way th
YüksekCVSS 8,8İstismar yokEPSS %7freeipa · freeipa27 Kas 2019
- CVE-2012-563136İzleyin
ipa 3.0 does not properly check server identity before sending credential containing cookies
YüksekCVSS 8,8İstismar yokEPSS %2freeipa · freeipa25 Kas 2019
- CVE-2017-1119136İzleyin
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action
YüksekCVSS 8,8İstismar yokEPSS %2freeipa · freeipa27 Eyl 2017
- CVE-2024-269835İzleyin
Freeipa: delegation rules allow a proxy service to impersonate any user to access another target service
YüksekCVSS 8,8İstismar yokEPSS %1freeipa · freeipa12 Haz 2024
- CVE-2026-1309734İzleyin
Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore
YüksekCVSS 8,7İstismar yokEPSS %0freeipa · freeipa20 Ağu 2026
- CVE-2017-259032İzleyin
A vulnerability was found in ipa before 4.4.
YüksekCVSS 8,1İstismar yokEPSS %1freeipa · freeipa27 Tem 2018
- CVE-2026-1955032İzleyin
Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes
YüksekCVSS 8,2İstismar yokEPSS %0freeipa · freeipa11 Ağu 2026
- CVE-2026-1186132İzleyin
Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships
YüksekCVSS 8,1İstismar yokEPSS %0freeipa · freeipa20 Ağu 2026
- CVE-2016-703031İzleyin
FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to
YüksekCVSS 7,5İstismar yokEPSS %5freeipa · freeipa28 Ağu 2017
- CVE-2017-1216931İzleyin
It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission.
YüksekCVSS 7,5İstismar yokEPSS %2freeipa · freeipa10 Oca 2018
- CVE-2015-517930İzleyin
FreeIPA might display user data improperly via vectors involving non-printable characters.
YüksekCVSS 7,5İstismar yokEPSS %1freeipa · freeipa20 Eyl 2017
- CVE-2016-541430İzleyin
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
YüksekCVSS 7,5İstismar yokEPSS %1freeipa · freeipa27 Haz 2017
- CVE-2026-7319830İzleyin
Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read
YüksekCVSS 7,5İstismar yokEPSS %0freeipa · freeipa20 Ağu 2026
- CVE-2026-7319730İzleyin
Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body read
YüksekCVSS 7,5İstismar yokEPSS %0freeipa · freeipa20 Ağu 2026
- CVE-2016-540427İzleyin
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke
OrtaCVSS 6,5İstismar yokEPSS %3freeipa · freeipa7 Eyl 2016
- CVE-2019-1019527İzleyin
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way th
OrtaCVSS 6,5İstismar yokEPSS %2freeipa · freeipa27 Kas 2019
- CVE-2023-545526İzleyin
Ipa: invalid csrf protection
OrtaCVSS 6,5İstismar yokEPSS %1freeipa · freeipa10 Oca 2024
- CVE-2026-7319626İzleyin
Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding
OrtaCVSS 6,5İstismar yokEPSS %0freeipa · freeipa20 Ağu 2026
- CVE-2016-957525İzleyin
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate prof
OrtaCVSS 6,3İstismar yokEPSS %1freeipa · freeipa13 Mar 2018
- CVE-2015-182721İzleyin
The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accou
OrtaCVSS 5,0İstismar yokEPSS %3freeipa · freeipa30 Mar 2015
- CVE-2020-172221İzleyin
A flaw was found in all ipa versions 4.x.x through 4.8.0.
OrtaCVSS 5,3İstismar yokEPSS %1freeipa · freeipa27 Nis 2020
- CVE-2014-785018İzleyin
Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or
OrtaCVSS 4,3İstismar yokEPSS %2freeipa · freeipa28 Kas 2014
- CVE-2019-1482617İzleyin
A flaw was found in FreeIPA versions 4.5.0 and later.
OrtaCVSS 4,4İstismar yokEPSS %0freeipa · freeipa17 Eyl 2019
- CVE-2014-782815İzleyin
FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the tw
DüşükCVSS 3,5İstismar yokEPSS %2freeipa · freeipa19 Kas 2014