Количество 10
Количество 10

CVE-2023-5455
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

CVE-2023-5455
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

CVE-2023-5455
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
CVE-2023-5455
A Cross-site request forgery vulnerability exists in ipa/session/login ...

ROS-20240402-09
Уязвимость IPA
GHSA-45hh-rj6v-548f
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
ELSA-2024-0145
ELSA-2024-0145: ipa security update (MODERATE)
ELSA-2024-0141
ELSA-2024-0141: ipa security update (MODERATE)

BDU:2024-02540
Уязвимость компонента login_password сервера FreeIpa, позволяющая нарушителю осуществить CSRF-атаку
ELSA-2024-0143
ELSA-2024-0143: idm:DL1 security update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2023-5455 A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
![]() | CVE-2023-5455 A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
![]() | CVE-2023-5455 A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
CVE-2023-5455 A Cross-site request forgery vulnerability exists in ipa/session/login ... | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
![]() | ROS-20240402-09 Уязвимость IPA | CVSS3: 6.5 | 0% Низкий | около 1 года назад |
GHSA-45hh-rj6v-548f A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
ELSA-2024-0145 ELSA-2024-0145: ipa security update (MODERATE) | больше 1 года назад | |||
ELSA-2024-0141 ELSA-2024-0141: ipa security update (MODERATE) | больше 1 года назад | |||
![]() | BDU:2024-02540 Уязвимость компонента login_password сервера FreeIpa, позволяющая нарушителю осуществить CSRF-атаку | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
ELSA-2024-0143 ELSA-2024-0143: idm:DL1 security update (MODERATE) | больше 1 года назад |
Уязвимостей на страницу