CVE-2020-1722: Medium severity red hat freeipa vulnerability
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
Other sources
A flaw was found in IPA. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
A vulnerability was found in IPA, where by sending a very long password (1.000.000 characters) it's possible to cause a denial a service attack on the server. This may lead to the website becoming unavailable or unresponsive. Usually, this problem is caused by a vulnerable password hashing implementation. When a long password is sent, the password hashing process will result in CPU and memory exhaustion.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-1722?
CVE-2020-1722 is classified as a denial of service vulnerability due to the potential for memory and CPU exhaustion.
How do I fix CVE-2020-1722?
To mitigate CVE-2020-1722, upgrade to versions 4.8.1 or later of the affected IPA software.
What versions are affected by CVE-2020-1722?
CVE-2020-1722 affects all IPA versions from 4.0.0 up to 4.8.0.
What happens if CVE-2020-1722 is exploited?
Exploiting CVE-2020-1722 can lead to a denial of service, causing the IPA server to become unresponsive.
Is CVE-2020-1722 specific to certain operating systems?
CVE-2020-1722 is most relevant to systems running Red Hat Enterprise Linux versions 6.0, 7.0, and 8.0 with affected IPA versions.