REDHAT-BUG-1160871: Medium severity freeipa vulnerability

Published Nov 5, 2014
·
Updated

A flaw was reported [1] in FreeIPA 4.0/4.1 where users could log in using only the OTP value. This arose because ipapwdauthentication() successfully determined that an empty password was invalid, but 389 itself would see this as an anonymous bind.

This will be fixed in the next release [2]. As support for OTP is not available in earlier versions, only FreeIPA >= 4.0 is affected.

[1] https://fedorahosted.org/freeipa/ticket/4690 [2] https://www.redhat.com/archives/freeipa-devel/2014-November/msg00068.html

Acknowledgements:

Red Hat would like to thank FreeIPA upstream for reporting this issue.

Statement:

This issue did not affect the versions of IPA as shipped with Red Hat Enterprise Linux 5, 6, or 7 as they did not include support for OTP.

Affected Software

1 affected component
Red Hat FreeIPA>=4.0

Event History

Nov 5, 2014
Data Sourced
via Red Hat·08:48 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1160871?

The severity of REDHAT-BUG-1160871 is considered to be high due to the potential for unauthorized access by allowing users to log in with only an OTP.

2

How do I fix REDHAT-BUG-1160871?

To fix REDHAT-BUG-1160871, you will need to update to the latest release of FreeIPA that addresses this vulnerability.

3

What versions of FreeIPA are affected by REDHAT-BUG-1160871?

FreeIPA versions 4.0 and 4.1 are affected by REDHAT-BUG-1160871.

4

Can REDHAT-BUG-1160871 allow anonymous access to the system?

Yes, REDHAT-BUG-1160871 allows users to log in anonymously due to the flaw in how password authentication is handled.

5

Is there a workaround for REDHAT-BUG-1160871 until a fix is available?

There is no officially recommended workaround for REDHAT-BUG-1160871, so updating to the fixed version is advised as soon as possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203