Search CVE reports


Toggle filters

31 – 34 of 34 results


CVE-2014-7828

High priority
Ignored

FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.

1 affected package

freeipa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa Not affected
Show less packages

CVE-2013-0199

Medium priority
Not affected

The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via...

1 affected package

freeipa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa
Show less packages

CVE-2013-0336

Medium priority
Ignored

The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection request...

2 affected packages

389-ds-base, freeipa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
389-ds-base
freeipa
Show less packages

CVE-2012-5484

Medium priority
Ignored

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

1 affected package

freeipa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freeipa
Show less packages