Vulnerabilities > Freeipa > Freeipa > 4.0.1

DATE CVE VULNERABILITY TITLE RISK
2024-01-10 CVE-2023-5455 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA.
network
low complexity
freeipa fedoraproject redhat CWE-352
6.5
2020-04-27 CVE-2020-1722 A flaw was found in all ipa versions 4.x.x through 4.8.0.
network
high complexity
freeipa redhat
5.3
2018-07-27 CVE-2017-2590 Permission Issues vulnerability in multiple products
A vulnerability was found in ipa before 4.4.
network
low complexity
freeipa redhat CWE-275
8.1
2017-09-28 CVE-2017-11191 Session Fixation vulnerability in Freeipa
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session.
network
low complexity
freeipa CWE-384
8.8
2017-09-21 CVE-2015-5284 Information Exposure vulnerability in Freeipa
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
network
low complexity
freeipa CWE-200
critical
9.8