İçeriğe atla
Noroxi

FreeIPA kayıtları

freeipa üreticisine ait 25 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%68
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

25 kayıt
  • CVE-2015-5284
    39İzleyin

    ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world read

    KritikCVSS 9,8İstismar yokEPSS %1

    freeipa · freeipa21 Eyl 2017

  • CVE-2019-14867
    37İzleyin

    A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way th

    YüksekCVSS 8,8İstismar yokEPSS %7

    freeipa · freeipa27 Kas 2019

  • CVE-2012-5631
    36İzleyin

    ipa 3.0 does not properly check server identity before sending credential containing cookies

    YüksekCVSS 8,8İstismar yokEPSS %2

    freeipa · freeipa25 Kas 2019

  • CVE-2017-11191
    36İzleyin

    FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action

    YüksekCVSS 8,8İstismar yokEPSS %2

    freeipa · freeipa27 Eyl 2017

  • CVE-2024-2698
    35İzleyin

    Freeipa: delegation rules allow a proxy service to impersonate any user to access another target service

    YüksekCVSS 8,8İstismar yokEPSS %1

    freeipa · freeipa12 Haz 2024

  • CVE-2026-13097
    34İzleyin

    Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore

    YüksekCVSS 8,7İstismar yokEPSS %0

    freeipa · freeipa20 Ağu 2026

  • CVE-2017-2590
    32İzleyin

    A vulnerability was found in ipa before 4.4.

    YüksekCVSS 8,1İstismar yokEPSS %1

    freeipa · freeipa27 Tem 2018

  • CVE-2026-19550
    32İzleyin

    Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes

    YüksekCVSS 8,2İstismar yokEPSS %0

    freeipa · freeipa11 Ağu 2026

  • CVE-2026-11861
    32İzleyin

    Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships

    YüksekCVSS 8,1İstismar yokEPSS %0

    freeipa · freeipa20 Ağu 2026

  • CVE-2016-7030
    31İzleyin

    FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to

    YüksekCVSS 7,5İstismar yokEPSS %5

    freeipa · freeipa28 Ağu 2017

  • CVE-2017-12169
    31İzleyin

    It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission.

    YüksekCVSS 7,5İstismar yokEPSS %2

    freeipa · freeipa10 Oca 2018

  • CVE-2015-5179
    30İzleyin

    FreeIPA might display user data improperly via vectors involving non-printable characters.

    YüksekCVSS 7,5İstismar yokEPSS %1

    freeipa · freeipa20 Eyl 2017

  • CVE-2016-5414
    30İzleyin

    FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.

    YüksekCVSS 7,5İstismar yokEPSS %1

    freeipa · freeipa27 Haz 2017

  • CVE-2026-73198
    30İzleyin

    Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read

    YüksekCVSS 7,5İstismar yokEPSS %0

    freeipa · freeipa20 Ağu 2026

  • CVE-2026-73197
    30İzleyin

    Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body read

    YüksekCVSS 7,5İstismar yokEPSS %0

    freeipa · freeipa20 Ağu 2026

  • CVE-2016-5404
    27İzleyin

    The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke

    OrtaCVSS 6,5İstismar yokEPSS %3

    freeipa · freeipa7 Eyl 2016

  • CVE-2019-10195
    27İzleyin

    A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way th

    OrtaCVSS 6,5İstismar yokEPSS %2

    freeipa · freeipa27 Kas 2019

  • CVE-2023-5455
    26İzleyin

    Ipa: invalid csrf protection

    OrtaCVSS 6,5İstismar yokEPSS %1

    freeipa · freeipa10 Oca 2024

  • CVE-2026-73196
    26İzleyin

    Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding

    OrtaCVSS 6,5İstismar yokEPSS %0

    freeipa · freeipa20 Ağu 2026

  • CVE-2016-9575
    25İzleyin

    Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate prof

    OrtaCVSS 6,3İstismar yokEPSS %1

    freeipa · freeipa13 Mar 2018

  • CVE-2015-1827
    21İzleyin

    The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accou

    OrtaCVSS 5,0İstismar yokEPSS %3

    freeipa · freeipa30 Mar 2015

  • CVE-2020-1722
    21İzleyin

    A flaw was found in all ipa versions 4.x.x through 4.8.0.

    OrtaCVSS 5,3İstismar yokEPSS %1

    freeipa · freeipa27 Nis 2020

  • CVE-2014-7850
    18İzleyin

    Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or

    OrtaCVSS 4,3İstismar yokEPSS %2

    freeipa · freeipa28 Kas 2014

  • CVE-2019-14826
    17İzleyin

    A flaw was found in FreeIPA versions 4.5.0 and later.

    OrtaCVSS 4,4İstismar yokEPSS %0

    freeipa · freeipa17 Eyl 2019

  • CVE-2014-7828
    15İzleyin

    FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the tw

    DüşükCVSS 3,5İstismar yokEPSS %2

    freeipa · freeipa19 Kas 2014