Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2024-2698
A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardabl…
Freeipa
4.11.2+
HIGH 8.8
CVE-2012-5631
ipa 3.0 does not properly check server identity before sending credential containing cookies
Freeipa
Mitigation only
MEDIUM 6.3
CVE-2016-9575
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in I…
Freeipa
Mitigation only
HIGH 7.5
CVE-2017-12169
It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authent…
Freeipa
Mitigation only
HIGH 8.8
CVE-2017-11191
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an o…
Freeipa
No fix yet
CRITICAL 9.8
CVE-2015-5284
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
Freeipa
after 4.2.1
HIGH 7.5
CVE-2015-5179
FreeIPA might display user data improperly via vectors involving non-printable characters.
Freeipa
after 4.5.0
HIGH 7.5
CVE-2016-7030
FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a d…
Freeipa
Mitigation only
HIGH 7.5
CVE-2016-5414
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
Freeipa
Patch available