CVE-2011-3636: CSRF
Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authentication of administrators for requests that make configuration changes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3636?
CVE-2011-3636 has a medium severity rating due to the potential for remote attackers to hijack administrator authentication.
How do I fix CVE-2011-3636?
To fix CVE-2011-3636, upgrade to FreeIPA version 2.1.4 or later where the vulnerability has been addressed.
What versions of FreeIPA are affected by CVE-2011-3636?
FreeIPA versions prior to 2.1.4, including 1.0.0 and 2.1.2, are affected by CVE-2011-3636.
What type of vulnerability is CVE-2011-3636?
CVE-2011-3636 is a Cross-site request forgery (CSRF) vulnerability affecting the management interface of FreeIPA.
Who can exploit CVE-2011-3636?
Remote attackers can exploit CVE-2011-3636 to hijack the authentication of administrators making configuration changes.