All errata/sisyphus/ALT-PU-2025-1392-7
ALT-PU-2025-1392-7

Package update freeipa in branch sisyphus

Version4.12.3-alt1
Published2026-08-28
Max severityHIGH
Severity:

Closed issues (3)

BDU:2026-06677
MEDIUM5.5

Уязвимость программного обеспечения централизованного управления идентификацией FreeIPA, позволяющая нарушителю получить доступ к конфиденциальным данным

Published: 2026-05-12Modified: 2026-08-31
CVSS 3.xMEDIUM 5.5
CVSS:3.x/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.0MEDIUM 4.6
CVSS:2.0/AV:L/AC:L/Au:S/C:C/I:N/A:N
CVE-2024-11029
MEDIUM5.5

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials.

Published: 2025-01-15Modified: 2026-06-17
CVSS 3.xMEDIUM 5.5
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE-2026-13097
HIGH8.7

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.

Published: 2026-08-20Modified: 2026-09-08
CVSS 3.xHIGH 8.7
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N