Freeipa
Freeipa: vulnerabilidades y CVE
Freeipa tiene 36 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE36
Últimos 12 meses13
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-18147 | Alta (8.1) | 0.34% | — | 9 sept 2026 | A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially… |
| CVE-2026-76561 | Alta (7.2) | 0.65% | — | 8 sept 2026 | A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated… |
| CVE-2026-79678 | Alta (8.1) | 0.68% | — | 7 sept 2026 | A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows… |
| CVE-2026-76578 | Crítica (9.8) | 0.97% | — | 7 sept 2026 | A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this,… |
| CVE-2026-73198 | Alta (7.5) | 0.43% | — | 20 ago 2026 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume… |
| CVE-2026-73197 | Alta (7.5) | 0.43% | — | 20 ago 2026 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler… |
| CVE-2026-73196 | Media (6.5) | 0.43% | — | 20 ago 2026 | A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without… |
| CVE-2026-13097 | Alta (8.7) | 0.43% | — | 20 ago 2026 | A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the… |
| CVE-2026-11861 | Alta (8.1) | 0.22% | — | 20 ago 2026 | A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and… |
| CVE-2026-19550 | Alta (8.2) | 0.29% | — | 11 ago 2026 | A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to… |
| CVE-2026-11610 | Alta (8.8) | 0.49% | — | 7 jul 2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted… |
| CVE-2026-14612 | Media (4.2) | 0.23% | — | 3 jul 2026 | Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity… |
| CVE-2026-11774 | Alta (7.6) | 0.68% | — | 11 jun 2026 | An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned… |
| CVE-2025-7493 | Crítica (9.1) | 0.56% | — | 30 sept 2025 | A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously… |
| CVE-2025-4404 | Crítica (9.1) | 2.0% | — | 17 jun 2025 | A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users… |
| CVE-2024-11029 | Media (5.5) | 0.23% | — | 15 ene 2025 | A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user… |
| CVE-2024-2698 | Alta (8.8) | 0.67% | — | 12 jun 2024 | A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a… |
| CVE-2024-1481 | Media (5.3) | 1.1% | — | 10 abr 2024 | A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of… |
| CVE-2023-5455 | Media (6.5) | 0.57% | — | 10 ene 2024 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as… |
| CVE-2020-1722 | Media (5.3) | 1.2% | — | 27 abr 2020 | A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of… |
| CVE-2019-14867 | Alta (8.8) | 7.4% | — | 27 nov 2019 | A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server,… |
| CVE-2019-10195 | Media (6.5) | 1.8% | — | 27 nov 2019 | A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user… |
| CVE-2012-5631 | Alta (8.8) | 1.8% | — | 25 nov 2019 | ipa 3.0 does not properly check server identity before sending credential containing cookies |
| CVE-2019-14826 | Media (4.4) | 0.34% | — | 17 sept 2019 | A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain… |
| CVE-2017-2590 | Alta (8.1) | 1.3% | — | 27 jul 2018 | A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could… |
| CVE-2016-9575 | Media (6.3) | 0.74% | — | 13 mar 2018 | Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker… |
| CVE-2017-12169 | Alta (7.5) | 1.9% | — | 10 ene 2018 | It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potentially use this flaw to disclose the… |
| CVE-2017-11191 | Alta (8.8) | 1.7% | — | 28 sept 2017 | FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an… |
| CVE-2015-5284 | Crítica (9.8) | 0.99% | — | 21 sept 2017 | ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable. |
| CVE-2015-5179 | Alta (7.5) | 1.1% | — | 20 sept 2017 | FreeIPA might display user data improperly via vectors involving non-printable characters. |