Количество 13
Количество 13
CVE-2025-4404
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
CVE-2025-4404
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
CVE-2025-4404
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
CVE-2025-4404
A privilege escalation from host to domain vulnerability was found in ...
RLSA-2025:9190
Important: ipa security update
GHSA-w66p-wgwc-mqmw
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
ELSA-2025-9190
ELSA-2025-9190: ipa security update (IMPORTANT)
ELSA-2025-9189
ELSA-2025-9189: ipa security update (IMPORTANT)
ELSA-2025-9188
ELSA-2025-9188: idm:DL1 security update (IMPORTANT)
ELSA-2025-9184
ELSA-2025-9184: ipa security update (IMPORTANT)
BDU:2025-04863
Уязвимость централизованной системы по управлению идентификацией пользователей FreeIPA, связанная с неправильным контролем доступа, позволяющая нарушителю повысить свои привилегии до уровня администратора домена и оказать воздействие на конфиденциальность целостность и доступость защищаемой информации
ROS-20250729-07
Уязвимость ipa-client
ROS-20250729-06
Уязвимость ipa-server
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
CVE-2025-4404 A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.  | CVSS3: 9.1  | 0% Низкий | 5 месяцев назад | |
CVE-2025-4404 A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.  | CVSS3: 9.1  | 0% Низкий | 5 месяцев назад | |
CVE-2025-4404 A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.  | CVSS3: 9.1  | 0% Низкий | 5 месяцев назад | |
CVE-2025-4404 A privilege escalation from host to domain vulnerability was found in ...  | CVSS3: 9.1  | 0% Низкий | 5 месяцев назад | |
RLSA-2025:9190 Important: ipa security update  | 0% Низкий | около 1 месяца назад | ||
GHSA-w66p-wgwc-mqmw A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.  | CVSS3: 9.1  | 0% Низкий | 5 месяцев назад | |
ELSA-2025-9190 ELSA-2025-9190: ipa security update (IMPORTANT)  | 4 месяца назад | |||
ELSA-2025-9189 ELSA-2025-9189: ipa security update (IMPORTANT)  | 4 месяца назад | |||
ELSA-2025-9188 ELSA-2025-9188: idm:DL1 security update (IMPORTANT)  | 5 месяцев назад | |||
ELSA-2025-9184 ELSA-2025-9184: ipa security update (IMPORTANT)  | 5 месяцев назад | |||
BDU:2025-04863 Уязвимость централизованной системы по управлению идентификацией пользователей FreeIPA, связанная с неправильным контролем доступа, позволяющая нарушителю повысить свои привилегии до уровня администратора домена и оказать воздействие на конфиденциальность целостность и доступость защищаемой информации  | CVSS3: 9.1  | 0% Низкий | 7 месяцев назад | |
ROS-20250729-07 Уязвимость ipa-client  | CVSS3: 9.1  | 0% Низкий | 3 месяца назад | |
ROS-20250729-06 Уязвимость ipa-server  | CVSS3: 9.1  | 0% Низкий | 3 месяца назад | 
Уязвимостей на страницу