REDHAT-BUG-2325557: Medium severity red hat freeipa vulnerability
The FreeIPA API audit sends the whole FreeIPA ccommand line to journalctl, as consequence during the FreeIPA installation process inadvertently ends up leaking the administrative user credentials (including the administrator password) to the journal database. On worst case scenario where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2325557?
The severity of REDHAT-BUG-2325557 is considered critical due to the leakage of administrative user credentials.
How do I fix REDHAT-BUG-2325557?
To fix REDHAT-BUG-2325557, ensure you update FreeIPA to the latest version where this issue has been patched.
Who is affected by REDHAT-BUG-2325557?
Users of FreeIPA who have installed the software are affected by REDHAT-BUG-2325557.
What are the risks associated with REDHAT-BUG-2325557?
The risks associated with REDHAT-BUG-2325557 include potential unauthorized access to sensitive administrative credentials.
When was REDHAT-BUG-2325557 reported?
REDHAT-BUG-2325557 was reported on October 9, 2023.