Product:

Freeipa

(Freeipa)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 18
Date Id Summary Products Score Patch Annotated
2017-06-27 CVE-2016-5414 FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services. Freeipa 7.5
2017-09-21 CVE-2015-5284 ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable. Freeipa 9.8
2017-09-20 CVE-2015-5179 FreeIPA might display user data improperly via vectors involving non-printable characters. Freeipa 7.5
2014-11-28 CVE-2014-7850 Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation. Freeipa N/A
2014-11-19 CVE-2014-7828 FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind. Freeipa N/A