All errata/sisyphus/ALT-PU-2018-1424-1
ALT-PU-2018-1424-1

Package update freeipa in branch sisyphus

Version4.6.3-alt3.S1
Published2018-03-15
Max severityHIGH
Severity:

Closed issues (1)

CVE-2017-11191
HIGH8.8

FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern

Published: 2017-09-28Modified: 2025-04-20
CVSS 2.0MEDIUM 6.5
CVSS:2.0/AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS 3.xHIGH 8.8
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H