First published: Wed Jul 27 2016(Updated: )
It was found that FreeIPA fails to check the CA ACLs properly, moreover the SAN name is incorrectly checked for service principals which means someone can request an arbitrary SAN name for services. The vulnerable code was added in the 4.4.0 release, which is not yet available in Fedora or RHEL.
Affected Software | Affected Version | How to fix |
---|---|---|
FreeIPA | >=4.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.