REDHAT-BUG-2364606: High severity FreeIPA FreeIPA vulnerability
Published May 6, 2025
·Updated
The lack of verification for the uniqueness of the LDAP attribute krbCanonicalName in FreeIPA may lead to privilege escalation from host to domain admin.
Affected Software
1 affected component
FreeIPA FreeIPA
Event History
May 6, 2025
Data Sourced
via Red Hat·10:20 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2364606?
The severity of REDHAT-BUG-2364606 is critical due to the potential for privilege escalation from host to domain admin.
2
How do I fix REDHAT-BUG-2364606?
To fix REDHAT-BUG-2364606, it is recommended to apply the latest updates and patches provided by FreeIPA.
3
What systems are affected by REDHAT-BUG-2364606?
REDHAT-BUG-2364606 affects instances of FreeIPA that do not verify the uniqueness of the LDAP attribute krbCanonicalName.
4
What could happen if REDHAT-BUG-2364606 is exploited?
If REDHAT-BUG-2364606 is exploited, it could allow an attacker to escalate privileges to the domain admin level.
5
Is there a workaround for REDHAT-BUG-2364606?
Currently, there is no official workaround for REDHAT-BUG-2364606; applying patches is the primary mitigation.