Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Freeipa HIGH 8.8
CVE-2024-2698

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardabl…

Fix: 4.11.2+
Fix from $1,950 2024-06-12
Freeipa HIGH 8.8
CVE-2012-5631

ipa 3.0 does not properly check server identity before sending credential containing cookies

Mitigation only
Fix from $1,950 2019-11-25
Freeipa MEDIUM 6.3
CVE-2016-9575

Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in I…

Mitigation only
Fix from $1,600 2018-03-13
Freeipa HIGH 7.5
CVE-2017-12169

It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authent…

Mitigation only
Fix from $1,950 2018-01-10
Freeipa HIGH 8.8
CVE-2017-11191

FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an o…

No fix yet
Fix from $1,950 2017-09-28
Freeipa CRITICAL 9.8
CVE-2015-5284

ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.

Fix: after 4.2.1
Fix from $2,300 2017-09-21
Freeipa HIGH 7.5
CVE-2015-5179

FreeIPA might display user data improperly via vectors involving non-printable characters.

Fix: after 4.5.0
Fix from $1,950 2017-09-20
Freeipa HIGH 7.5
CVE-2016-7030

FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a d…

Mitigation only
Fix from $1,950 2017-08-28
Freeipa HIGH 7.5
CVE-2016-5414

FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.

Patch available
Fix from $1,950 2017-06-27