Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-0141

Опубликовано: 11 янв. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-0141: ipa security update (MODERATE)

[4.10.2-5.0.1]

  • Resolves: 2242828 Invalid CSRF protection (CVE-2023-5455)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

ipa-client

4.10.2-5.0.1.el9_3

ipa-client-common

4.10.2-5.0.1.el9_3

ipa-client-epn

4.10.2-5.0.1.el9_3

ipa-client-samba

4.10.2-5.0.1.el9_3

ipa-common

4.10.2-5.0.1.el9_3

ipa-selinux

4.10.2-5.0.1.el9_3

ipa-server

4.10.2-5.0.1.el9_3

ipa-server-common

4.10.2-5.0.1.el9_3

ipa-server-dns

4.10.2-5.0.1.el9_3

ipa-server-trust-ad

4.10.2-5.0.1.el9_3

python3-ipaclient

4.10.2-5.0.1.el9_3

python3-ipalib

4.10.2-5.0.1.el9_3

python3-ipaserver

4.10.2-5.0.1.el9_3

python3-ipatests

4.10.2-5.0.1.el9_3

Oracle Linux x86_64

ipa-client

4.10.2-5.0.1.el9_3

ipa-client-common

4.10.2-5.0.1.el9_3

ipa-client-epn

4.10.2-5.0.1.el9_3

ipa-client-samba

4.10.2-5.0.1.el9_3

ipa-common

4.10.2-5.0.1.el9_3

ipa-selinux

4.10.2-5.0.1.el9_3

ipa-server

4.10.2-5.0.1.el9_3

ipa-server-common

4.10.2-5.0.1.el9_3

ipa-server-dns

4.10.2-5.0.1.el9_3

ipa-server-trust-ad

4.10.2-5.0.1.el9_3

python3-ipaclient

4.10.2-5.0.1.el9_3

python3-ipalib

4.10.2-5.0.1.el9_3

python3-ipaserver

4.10.2-5.0.1.el9_3

python3-ipatests

4.10.2-5.0.1.el9_3

Связанные CVE

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

CVSS3: 6.5
redhat
больше 1 года назад

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

CVSS3: 6.5
nvd
больше 1 года назад

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

CVSS3: 6.5
debian
больше 1 года назад

A Cross-site request forgery vulnerability exists in ipa/session/login ...

CVSS3: 6.5
redos
около 1 года назад

Уязвимость IPA