RHSA-2024:3757: Important: ipa security update
Important: ipa security update
Other sources
Red Hat Identity Management (IdM) is a centralized authentication, identitymanagement, and authorization solution for both traditional and cloud-basedenterprise environments.Security Fix(es): freeipa: delegation rules allow a proxy service to impersonate any user to access another target service (CVE-2024-2698) freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force (CVE-2024-3183)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3757?
RHSA-2024:3757 has an important severity rating due to vulnerabilities in the ipa component.
How do I fix RHSA-2024:3757?
To remediate RHSA-2024:3757, update to the version 4.10.1-12.el9_2.2 for the affected packages.
Which products are affected by RHSA-2024:3757?
RHSA-2024:3757 affects multiple Red Hat products including Red Hat Enterprise Linux for x86_64 and Power architecture.
What are the key vulnerabilities in RHSA-2024:3757?
RHSA-2024:3757 addresses vulnerabilities related to delegation rules in the freeipa package.
Is there a specific remediation for the ipa-server component in RHSA-2024:3757?
Yes, patch the ipa-server component to version 4.10.1-12.el9_2.2 to resolve vulnerabilities described in RHSA-2024:3757.