Known vulnerabilities in freeipa
Vendor:
Fedoraproject
Software:
freeipa
Software CPE:
cpe:2.3:o:fedoraproject:freeipa:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
36
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
4.13.2-1.fc43
4.13.2-1.fc44
4.13.2-1.fc45
4.13.1-16.fc45.2
4.13.1-7.fc43
4.13.1-12.fc44
4.13.1-16.fc45
4.12.5-1.fc41
4.12.5-1.fc42
4.7.4-1.fc29
4.8.3-1.fc30
4.8.3-1.fc31
4.6.4-2.fc27
4.4.3-2.fc25
4.4.3-1.fc25
4.3.2-4.fc24
4.3.2-3.fc24
4.4.2-2.fc25
4.3.2-2.fc25
4.3.2-2.fc24
4.2.4-2.fc23
4.2.2-1.fc23
4.1.4-1.fc21
4.1.4-1.fc22
4.1.1-2.fc21
4.1.1-1.fc21
4.11.1-2.fc39
4.10.3-2.fc38
4.12.2-3.fc40
4.12.2-7.fc41
4.10.0-6.fc37
4.9.6-3.fc33
4.9.6-4.fc34
4.9.7-4.fc35
4.9.7-4.fc36
4.9.2-4.fc32
4.9.2-4.fc33
4.9.2-4.fc34
4.12.1-1.fc39
4.12.1-1.fc40
4.11.1-4.fc40
4.11.1-4.fc41
4.10.3-1.fc38
4.11.1-1.fc39
4.11.1-1.fc40
Vulnerabilities (36)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139941 - Out-of-bounds write CVE-2026-6949 |
CWE-787 | Medium | 4.13.2-1.fc43, 4.13.2-1.fc44, 4.13.2-1.fc45 | 28.07.2026 |
SB2026072905 SB2026072928 SB2026072935 and 14 more |
||
| #VU139942 - Out-of-bounds read CVE-2026-58216 |
CWE-125 | Low | 4.13.2-1.fc43, 4.13.2-1.fc44, 4.13.2-1.fc45 | 28.07.2026 |
SB2026072905 SB2026072928 SB2026072935 and 14 more |
||
| #VU139943 - Resource exhaustion CVE-2026-58218 |
CWE-400 | Medium | 4.13.2-1.fc43, 4.13.2-1.fc44, 4.13.2-1.fc45 | 28.07.2026 |
SB2026072905 SB2026072928 SB2026072935 and 14 more |
||
| #VU139944 - Improper Access Control CVE-2026-58221 |
CWE-284 | Medium | 4.13.2-1.fc43, 4.13.2-1.fc44, 4.13.2-1.fc45 | 28.07.2026 |
SB2026072905 SB2026072928 SB2026072935 and 14 more |
||
| #VU139945 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-58222 |
CWE-89 | Low | 4.13.2-1.fc43, 4.13.2-1.fc44, 4.13.2-1.fc45 | 28.07.2026 |
SB2026072905 SB2026072928 SB2026072935 and 14 more |
||
| #VU139946 - Improper input validation CVE-2026-58224 |
CWE-20 | Medium | 4.13.2-1.fc43, 4.13.2-1.fc44, 4.13.2-1.fc45 | 28.07.2026 |
SB2026072905 SB2026072928 SB2026072935 and 14 more |
||
| #VU132340 - Improper Access Control CVE-2026-1933 |
CWE-284 | Low | 4.13.1-7.fc43, 4.13.1-12.fc44, 4.13.1-16.fc45 | 27.05.2026 |
SB2026052704 SB2026052705 SB2026052711 and 11 more |
||
| #VU132341 - Improper Access Control CVE-2026-2340 |
CWE-284 | Low | 4.13.1-7.fc43, 4.13.1-12.fc44, 4.13.1-16.fc45 | 27.05.2026 |
SB2026052704 SB2026052705 SB2026052707 and 17 more |
||
| #VU132342 - Improper Certificate Validation CVE-2026-3012 |
CWE-295 | High | 4.13.1-7.fc43, 4.13.1-12.fc44, 4.13.1-16.fc45 | 27.05.2026 |
SB2026052704 SB2026052705 SB2026052708 and 14 more |
||
| #VU132343 - NULL Pointer Dereference CVE-2026-3238 |
CWE-476 | Medium | 4.13.1-7.fc43, 4.13.1-12.fc44, 4.13.1-16.fc45 | 27.05.2026 |
SB2026052704 SB2026052705 SB2026052707 and 13 more |
||
| #VU132344 - Command injection CVE-2026-4408 |
CWE-77 | High | 4.13.1-7.fc43, 4.13.1-12.fc44, 4.13.1-16.fc45 | 27.05.2026 |
SB2026052704 SB2026052705 SB2026052707 and 20 more |
||
| #VU132345 - Command injection CVE-2026-4480 |
CWE-77 | High | 4.13.1-7.fc43, 4.13.1-12.fc44, 4.13.1-16.fc45 | 27.05.2026 |
SB2026052704 SB2026052705 SB2026052707 and 18 more |
||
| #VU116216 - Insufficient Granularity of Access Control CVE-2025-7493 |
CWE-1220 | Medium | 4.12.5-1.fc41, 4.12.5-1.fc42 | 01.10.2025 |
SB2025100120 SB2025100123 SB2025100124 and 14 more |
||
| #VU103304 - Information Exposure Through Log Files CVE-2024-11029 |
CWE-532 | Low | 4.12.2-3.fc40, 4.12.2-7.fc41 | 24.01.2025 |
SB2025012493 SB2025012494 SB2025012496 and 1 more |
||
| #VU92249 - Use of Password Hash With Insufficient Computational Effort CVE-2024-3183 |
CWE-916 | Low | 4.12.1-1.fc39, 4.12.1-1.fc40 | 19.06.2024 |
SB2024061917 SB2024061918 SB2024061919 and 11 more |
||
| #VU92247 - Improper Authorization CVE-2024-2698 |
CWE-285 | Medium | 4.12.1-1.fc39, 4.12.1-1.fc40 | 19.06.2024 |
SB2024061917 SB2024061919 SB2024061920 and 5 more |
||
| #VU87167 - Improper input validation CVE-2024-1481 |
CWE-20 | Medium | 4.10.3-2.fc38, 4.11.1-2.fc39, 4.11.1-4.fc40, 4.11.1-4.fc41 | 06.03.2024 |
SB2024030645 SB2024030665 SB2024030666 and 5 more |
||
| #VU85268 - Cross-Site Request Forgery (CSRF) CVE-2023-5455 |
CWE-352 | Medium | 4.10.3-1.fc38, 4.11.1-1.fc39, 4.11.1-1.fc40 | 10.01.2024 |
SB2024011032 SB2024011039 SB2024011040 and 17 more |
||
| #VU67271 - Incorrect Default Permissions CVE-2022-32743 |
CWE-276 | Medium | 4.10.0-6.fc37 | 13.09.2022 |
SB2022091372 SB2022091377 SB2022111138 and 5 more |
||
| #VU67270 - Use of Insufficiently Random Values CVE-2022-1615 |
CWE-330 | Low | 4.10.0-6.fc37 | 13.09.2022 |
SB2022091371 SB2022091377 SB2022091448 and 18 more |
Showing elements 1 - 20 out of 36