Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Freeipa
(Freeipa)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 18 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2017-06-27 | CVE-2016-5414 | FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services. | Freeipa | 7.5 | ||
2017-09-21 | CVE-2015-5284 | ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable. | Freeipa | 9.8 | ||
2017-09-20 | CVE-2015-5179 | FreeIPA might display user data improperly via vectors involving non-printable characters. | Freeipa | 7.5 | ||
2014-11-28 | CVE-2014-7850 | Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation. | Freeipa | N/A | ||
2014-11-19 | CVE-2014-7828 | FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind. | Freeipa | N/A |