ALT-PU-2018-1424-1

Обновление пакета freeipa в ветке sisyphus

Версия4.6.3-alt3.S1
Задание#201801
Опубликовано2018-03-15
Макс. серьёзностьHIGH
Серьёзность:

Закрытые проблемы (1)

CVE-2017-11191
HIGH8.8

FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern

Опубликовано: 2017-09-28Изменено: 2025-04-20
CVSS 2.0СРЕДНЯЯ 6.5
CVSS:2.0/AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS 3.xВЫСОКАЯ 8.8
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H