CVE-2012-5631: High severity red hat freeipa vulnerability
Published Nov 25, 2019
·Updated
ipa 3.0 does not properly check server identity before sending credential containing cookies
Affected Software
1 affected component
FreeIPA FreeIPA=3.0.0
Event History
Nov 25, 2019
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2012-5631?
CVE-2012-5631 has a medium severity rating due to improper server identity checking that may expose sensitive credentials.
2
How do I fix CVE-2012-5631?
To fix CVE-2012-5631, upgrade to a newer version of FreeIPA that includes the appropriate security patches.
3
What are the potential risks associated with CVE-2012-5631?
The risks of CVE-2012-5631 include the potential exposure of sensitive cookies and credentials to malicious actors.
4
Which versions of FreeIPA are affected by CVE-2012-5631?
FreeIPA version 3.0.0 is specifically affected by CVE-2012-5631.
5
Is CVE-2012-5631 a local or remote vulnerability?
CVE-2012-5631 is considered a remote vulnerability as it involves improper identity checks during communications with servers.