CVE-2017-11191: High severity red hat freeipa vulnerability
DISPUTED FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11191?
CVE-2017-11191 is considered a moderate severity vulnerability due to its potential to allow account-locking restrictions to be bypassed.
How do I fix CVE-2017-11191?
To fix CVE-2017-11191, upgrade FreeIPA to a version that is confirmed to be unaffected by this vulnerability as indicated by the vendor.
What versions of FreeIPA are affected by CVE-2017-11191?
CVE-2017-11191 affects FreeIPA versions from 4.0.0 up to 4.6.1.
What type of attack does CVE-2017-11191 enable?
CVE-2017-11191 enables an attacker to perform a session hijacking by using an old session ID to bypass locking mechanisms.
Who is impacted by CVE-2017-11191?
Remote authenticated users of affected versions of FreeIPA are at risk from CVE-2017-11191.