CVE-2014-7828: Low severity red hat freeipa vulnerability
A flaw was reported [1] in FreeIPA 4.0/4.1 where users could log in using only the OTP value. This arose because ipapwdauthentication() successfully determined that an empty password was invalid, but 389 itself would see this as an anonymous bind.
This will be fixed in the next release [2]. As support for OTP is not available in earlier versions, only FreeIPA >= 4.0 is affected.
[1] https://fedorahosted.org/freeipa/ticket/4690 [2] https://www.redhat.com/archives/freeipa-devel/2014-November/msg00068.html
Acknowledgements:
Red Hat would like to thank FreeIPA upstream for reporting this issue.
Statement:
This issue did not affect the versions of IPA as shipped with Red Hat Enterprise Linux 5, 6, or 7 as they did not include support for OTP.
Other sources
FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7828?
CVE-2014-7828 has a medium severity due to the potential for unauthorized access using only the OTP value.
How do I fix CVE-2014-7828?
To fix CVE-2014-7828, upgrade FreeIPA to version 4.1.1 or later.
Which versions of FreeIPA are affected by CVE-2014-7828?
FreeIPA versions 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, and 4.1.1 are affected by CVE-2014-7828.
What is impacted by CVE-2014-7828?
CVE-2014-7828 impacts the authentication mechanism, allowing users to log in with an OTP alone.
Is there a workaround for CVE-2014-7828?
No official workaround is provided for CVE-2014-7828; upgrading to the fixed version is recommended.