REDHAT-BUG-1160871: Medium severity freeipa vulnerability
A flaw was reported [1] in FreeIPA 4.0/4.1 where users could log in using only the OTP value. This arose because ipapwdauthentication() successfully determined that an empty password was invalid, but 389 itself would see this as an anonymous bind.
This will be fixed in the next release [2]. As support for OTP is not available in earlier versions, only FreeIPA >= 4.0 is affected.
[1] https://fedorahosted.org/freeipa/ticket/4690 [2] https://www.redhat.com/archives/freeipa-devel/2014-November/msg00068.html
Acknowledgements:
Red Hat would like to thank FreeIPA upstream for reporting this issue.
Statement:
This issue did not affect the versions of IPA as shipped with Red Hat Enterprise Linux 5, 6, or 7 as they did not include support for OTP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1160871?
The severity of REDHAT-BUG-1160871 is considered to be high due to the potential for unauthorized access by allowing users to log in with only an OTP.
How do I fix REDHAT-BUG-1160871?
To fix REDHAT-BUG-1160871, you will need to update to the latest release of FreeIPA that addresses this vulnerability.
What versions of FreeIPA are affected by REDHAT-BUG-1160871?
FreeIPA versions 4.0 and 4.1 are affected by REDHAT-BUG-1160871.
Can REDHAT-BUG-1160871 allow anonymous access to the system?
Yes, REDHAT-BUG-1160871 allows users to log in anonymously due to the flaw in how password authentication is handled.
Is there a workaround for REDHAT-BUG-1160871 until a fix is available?
There is no officially recommended workaround for REDHAT-BUG-1160871, so updating to the fixed version is advised as soon as possible.