Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5455

Опубликовано: 10 янв. 2024
Источник: redhat
CVSS3: 6.5

Описание

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

Отчет

The CSRF vulnerability in ipa/session/login_password is considered a moderate issue due to the need for the attacker to trick users into submitting a request. This implies that exploitation requires user interaction for a new authentication attempt, rather than reflecting a cookie for an already logged-in user. While the vulnerability could result in a loss of confidentiality and system integrity, the specific actions and their severity are not explicitly detailed. The moderate classification suggests that, while serious, the limitations on exploitation conditions and potential impact contribute to a moderate overall severity.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ipaOut of support scope
Red Hat Enterprise Linux 8idm:client/ipaNot affected
Red Hat Enterprise Linux 8krb5Affected
Red Hat Enterprise Linux 7ipaFixedRHSA-2024:014510.01.2024
Red Hat Enterprise Linux 8idmFixedRHSA-2024:014310.01.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportidmFixedRHSA-2024:014410.01.2024
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceidmFixedRHSA-2024:014410.01.2024
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsidmFixedRHSA-2024:014410.01.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportidmFixedRHSA-2024:013810.01.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceidmFixedRHSA-2024:013810.01.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

CVSS3: 6.5
nvd
больше 1 года назад

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

CVSS3: 6.5
debian
больше 1 года назад

A Cross-site request forgery vulnerability exists in ipa/session/login ...

CVSS3: 6.5
redos
больше 1 года назад

Уязвимость IPA

CVSS3: 6.5
github
больше 1 года назад

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

6.5 Medium

CVSS3