First published: Mon Sep 21 2015(Updated: )
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ipa | <4.2.2 | 4.2.2 |
Red Hat FreeIPA | <=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5284 is considered a critical vulnerability due to exposure of sensitive certificate and private key information.
To fix CVE-2015-5284, upgrade FreeIPA to version 4.2.2 or later.
The vulnerable file associated with CVE-2015-5284 is /etc/httpd/alias/kra-agent.pem.
CVE-2015-5284 can lead to unauthorized access to the CA agent certificate and private key, compromising the security of the FreeIPA installation.
Versions of FreeIPA prior to 4.2.2, including 4.2.1 and earlier, are vulnerable to CVE-2015-5284.