Vulnerabilities > Freeipa > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-06-27 | CVE-2016-5414 | Improper Access Control vulnerability in Freeipa 4.4.0 FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services. | 5.0 |
2016-09-07 | CVE-2016-5404 | Improper Access Control vulnerability in multiple products The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission. | 6.5 |
2014-11-28 | CVE-2014-7850 | Cross-Site Scripting vulnerability in Freeipa Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation. | 4.3 |