CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6617

As cited

Copy frozen at (site build).

vulnerabilities

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

FreeIPA contains a flaw that allows an unauthenticated client to create an arbitrary Kerberos identity and gain administrator group membership, according to Red Hat. The vulnerability requires a secondary vulnerability in the underlying 389 Directory Server database software to be exploited. The attack chain enables an anonymous attacker to establish reusable administrative credentials within a Linux domain environment.

Why it matters: Linux domain administrators and organizations using FreeIPA for identity management should assess their exposure immediately, as this flaw allows unauthenticated privilege escalation that could compromise all systems trusting the directory service.

VendorsLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary