As cited
Copy frozen at (site build).
vulnerabilities
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
FreeIPA contains a flaw that allows an unauthenticated client to create an arbitrary Kerberos identity and gain administrator group membership, according to Red Hat. The vulnerability requires a secondary vulnerability in the underlying 389 Directory Server database software to be exploited. The attack chain enables an anonymous attacker to establish reusable administrative credentials within a Linux domain environment.
Why it matters: Linux domain administrators and organizations using FreeIPA for identity management should assess their exposure immediately, as this flaw allows unauthenticated privilege escalation that could compromise all systems trusting the directory service.
- Source published
- First seen by Cybersecurity Tracker