Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-1481

Опубликовано: 20 фев. 2024
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

Отчет

This vulnerability poses a moderate severity risk due to its potential for a denial of service (DoS) attack and limited exploitation scope. While it allows for influencing the arguments passed to the kinit command, thereby potentially disrupting authentication processes and causing service interruptions, it does not grant unauthorized access to sensitive resources or compromise the integrity of the system. The restricted access rights of the 'ipaapi' user limit the impact to denial of service scenarios, mitigating the risk of unauthorized authentication or access to other accounts via keytab files or cached credentials. Furthermore, the vulnerability does not enable the extraction of sensitive information or the execution of arbitrary commands beyond the context of the kinit command.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ipaOut of support scope
Red Hat Enterprise Linux 8idmFixedRHSA-2024:304422.05.2024
Red Hat Enterprise Linux 8idmFixedRHSA-2024:304422.05.2024
Red Hat Enterprise Linux 9ipaFixedRHSA-2024:214730.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2262169freeipa: specially crafted HTTP requests potentially lead to denial of service

EPSS

Процентиль: 48%
0.00246
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

CVSS3: 5.3
nvd
больше 1 года назад

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

CVSS3: 5.3
debian
больше 1 года назад

A flaw was found in FreeIPA. This issue may allow a remote attacker to ...

CVSS3: 5.3
github
больше 1 года назад

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

oracle-oval
около 1 года назад

ELSA-2024-3044: idm:DL1 security update (MODERATE)

EPSS

Процентиль: 48%
0.00246
Низкий

5.3 Medium

CVSS3