Vulnerabilities
Vulnerable Software
Freeipa:  >> Freeipa  >> 4.2.1  Security Vulnerabilities
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern
CVSS Score
8.8
EPSS Score
0.017
Published
2017-09-28
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
CVSS Score
9.8
EPSS Score
0.01
Published
2017-09-21
FreeIPA might display user data improperly via vectors involving non-printable characters.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-09-20


Contact Us

Shodan ® - All rights reserved