Freeipa
22 known vulnerabilities
Top Products
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages`
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversize
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attribut
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Direct
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before
ipa 3.0 does not properly check server identity before sending credential containing cookies
A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attack
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modify
It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users'
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions v
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem,
FreeIPA might display user data improperly via vectors involving non-printable characters.
FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
Frequently Asked Questions
How many CVEs affect Freeipa?
Freeipa has 22 CVE records in our database, including 2 critical and 12 high severity vulnerabilities.
What are the most severe Freeipa vulnerabilities?
Freeipa has 2 critical severity (CVSS 9.0+) and 12 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Freeipa vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Freeipa products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Freeipa Vulnerabilities
CyberStrike scans your infrastructure for Freeipa vulnerabilities and provides real-time remediation guidance.
Get Started