Vulnerabilities > Freeipa > Freeipa > 4.0.3

DATE CVE VULNERABILITY TITLE RISK
2024-01-10 CVE-2023-5455 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA.
network
low complexity
freeipa fedoraproject redhat CWE-352
6.5
2020-04-27 CVE-2020-1722 Resource Exhaustion vulnerability in multiple products
A flaw was found in all ipa versions 4.x.x through 4.8.0.
network
high complexity
freeipa redhat CWE-400
5.3
2018-07-27 CVE-2017-2590 Permission Issues vulnerability in multiple products
A vulnerability was found in ipa before 4.4.
network
low complexity
freeipa redhat CWE-275
5.5
2017-09-28 CVE-2017-11191 Session Fixation vulnerability in Freeipa
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session.
network
low complexity
freeipa CWE-384
8.8
2017-09-21 CVE-2015-5284 Information Exposure vulnerability in Freeipa
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
network
low complexity
freeipa CWE-200
5.0
2017-09-20 CVE-2015-5179 Improper Input Validation vulnerability in Freeipa
FreeIPA might display user data improperly via vectors involving non-printable characters.
network
low complexity
freeipa CWE-20
5.0
2014-11-28 CVE-2014-7850 Cross-Site Scripting vulnerability in Freeipa
Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.
network
freeipa CWE-79
4.3
2014-11-19 CVE-2014-7828 Permissions, Privileges, and Access Controls vulnerability in Freeipa
FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.
network
freeipa CWE-264
3.5