Vulnerabilities
Vulnerable Software
Freeipa:  >> Freeipa  >> 4.0.0  Security Vulnerabilities
FreeIPA might display user data improperly via vectors involving non-printable characters.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-09-20
The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.
CVSS Score
5.0
EPSS Score
0.026
Published
2015-03-30
Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.
CVSS Score
4.3
EPSS Score
0.019
Published
2014-11-28
FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.
CVSS Score
3.5
EPSS Score
0.021
Published
2014-11-19


Contact Us

Shodan ® - All rights reserved