Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-11029

Опубликовано: 15 янв. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials.

Отчет

This vulnerability doesn't affect FreeIPA (IPA) versions as shipped with Red Hat Enterprise Linux versions before Red Hat Enterprise Linux 9.5 as it doesn't have the API audit implemented.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10ipaNot affected
Red Hat Enterprise Linux 7ipaNot affected
Red Hat Enterprise Linux 8idm:client/ipaNot affected
Red Hat Enterprise Linux 8idm:DL1/ipaNot affected
Red Hat Enterprise Linux 9ipaFixedRHSA-2025:033415.01.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-497
https://bugzilla.redhat.com/show_bug.cgi?id=2325557freeipa: Administrative user data leaked through systemd journal

EPSS

Процентиль: 6%
0.00027
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
7 месяцев назад

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials.

CVSS3: 5.5
nvd
7 месяцев назад

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials.

CVSS3: 5.5
debian
7 месяцев назад

A flaw was found in the FreeIPA API audit, where it sends the whole Fr ...

CVSS3: 5.5
github
7 месяцев назад

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials.

oracle-oval
7 месяцев назад

ELSA-2025-0334: ipa security update (MODERATE)

EPSS

Процентиль: 6%
0.00027
Низкий

5.5 Medium

CVSS3