CVE-2017-12169: Infoleak
An information disclosure vulnerability has been found in ipa allowing attacker to retrieve user password hash when utilizing 'System: Read Stage Users' permission.
Other sources
It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potentially use this flaw to disclose the password hashes belonging to Stage Users. This security issue does not result in disclosure of password hashes belonging to active standard users. NOTE: some developers feel that this report is a suggestion for a design change to Stage User activation, not a statement of a vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12169?
CVE-2017-12169 has been classified as a medium-severity vulnerability.
How do I fix CVE-2017-12169?
To address CVE-2017-12169, upgrade to FreeIPA version 4.5.0 or later.
What systems are affected by CVE-2017-12169?
FreeIPA version 4.2.0 and later are affected by CVE-2017-12169.
What kind of attack does CVE-2017-12169 enable?
CVE-2017-12169 allows an attacker with 'System: Read Stage Users' permission to retrieve user password hashes.
Is CVE-2017-12169 considered a critical vulnerability?
CVE-2017-12169 is not considered critical, but it poses a significant security risk to affected systems.