Vulnerabilities > Freeipa

DATE CVE VULNERABILITY TITLE RISK
2017-09-21 CVE-2015-5284 Information Exposure vulnerability in Freeipa
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
network
low complexity
freeipa CWE-200
5.0
2017-09-20 CVE-2015-5179 Improper Input Validation vulnerability in Freeipa
FreeIPA might display user data improperly via vectors involving non-printable characters.
network
low complexity
freeipa CWE-20
5.0
2017-08-28 CVE-2016-7030 Credentials Management vulnerability in Freeipa 4.6.0
FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.
network
low complexity
freeipa CWE-255
5.0
2017-06-27 CVE-2016-5414 Improper Access Control vulnerability in Freeipa 4.4.0
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
network
low complexity
freeipa CWE-284
5.0
2016-09-07 CVE-2016-5404 Improper Access Control vulnerability in multiple products
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
network
low complexity
freeipa oracle fedoraproject CWE-284
6.5
2014-11-28 CVE-2014-7850 Cross-Site Scripting vulnerability in Freeipa
Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.
network
freeipa CWE-79
4.3
2014-11-19 CVE-2014-7828 Permissions, Privileges, and Access Controls vulnerability in Freeipa
FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.
network
freeipa CWE-264
3.5