Vulnerabilities (CVE)

Filtered by vendor Freeipa Subscribe
Filtered by product Freeipa
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-7828 1 Freeipa 1 Freeipa 2017-09-08 3.5 LOW N/A
FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.
CVE-2015-1827 2 Fedoraproject, Freeipa 2 Fedora, Freeipa 2016-12-31 5.0 MEDIUM N/A
The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.
CVE-2014-7850 1 Freeipa 1 Freeipa 2015-02-17 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.