Known vulnerabilities in freeipa - page 2

Software: freeipa
Software CPE: cpe:2.3:o:fedoraproject:freeipa:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 36
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting freeipa freeipa is affected by 36 known vulnerabilities: 6 high, 19 medium, 11 low Critical High Medium Low

Vulnerabilities (36)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU58098 - Improper Access Control
CVE-2016-2124
CWE-284 High
No
No
4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 10.11.2021 SB2021111008
SB2021111201
SB2021112913
and 34 more
#VU58097 - Permissions, Privileges, and Access Controls
CVE-2020-25717
CWE-264 Medium
No
No
4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 10.11.2021 SB2021111008
SB2021111201
SB2021112913
and 43 more
#VU58096 - Permissions, Privileges, and Access Controls
CVE-2020-25718
CWE-264 Medium
No
No
4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 10.11.2021 SB2021111008
SB2021111201
SB2022012012
and 11 more
#VU58095 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-25719
CWE-362 Low
No
No
4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 10.11.2021 SB2021111008
SB2021111201
SB2021121644
and 17 more
#VU58094 - Improper Authentication
CVE-2020-25721
CWE-287 Medium
No
No
4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 10.11.2021 SB2021111008
SB2021111201
SB2022012012
and 13 more
#VU58093 - Permissions, Privileges, and Access Controls
CVE-2020-25722
CWE-264 Medium
No
No
4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 10.11.2021 SB2021111008
SB2021111201
SB2021113012
and 14 more
#VU58092 - Use After Free
CVE-2021-3738
CWE-416 Medium
No
No
4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 10.11.2021 SB2021111008
SB2021111201
SB2022012012
and 11 more
#VU58091 - Improper input validation
CVE-2021-23192
CWE-20 Medium
No
No
4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 10.11.2021 SB2021111008
SB2021111201
SB2021112914
and 19 more
#VU54105 - Exposure of sensitive information to an unauthorized actor
CVE-2020-35518
CWE-200 Medium
No
No
4.9.2-4.fc32, 4.9.2-4.fc33, 4.9.2-4.fc34 15.06.2021 SB2021061502
SB2021061505
SB2021062118
and 12 more
#VU26103 - Improper input validation
CVE-2019-14867
CWE-20 High
No
No
4.7.4-1.fc29, 4.8.3-1.fc30, 4.8.3-1.fc31 17.03.2020 SB2019112719
SB2019121718
SB2020040168
and 4 more
#VU26102 - Information Exposure Through Log Files
CVE-2019-10195
CWE-532 Low
No
No
4.7.4-1.fc29, 4.8.3-1.fc30, 4.8.3-1.fc31 17.03.2020 SB2019112719
SB2019121718
SB2020040168
and 4 more
#VU36812 - Improper input validation
CVE-2017-2590
CWE-20 High
No
No
4.4.3-2.fc25 27.07.2018 SB2018072718
SB2017022711
SB2017030214
#VU37442 - Improper Authorization
CVE-2016-9575
CWE-285 Medium
No
No
4.3.2-3.fc24, 4.3.2-4.fc24, 4.4.2-2.fc25, 4.4.3-1.fc25 13.03.2018 SB2018031342
SB2016121511
SB2016121512
and 3 more
#VU38415 - Credentials Management
CVE-2016-7030
CWE-255 Medium
No
No
4.3.2-3.fc24, 4.3.2-4.fc24, 4.4.2-2.fc25, 4.4.3-1.fc25 28.08.2017 SB2017082811
SB2016121511
SB2016121512
and 3 more
#VU41054 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2014-7850
CWE-79 Low
No
No
4.1.1-2.fc21 28.11.2014 SB2014111901
SB2014112102
#VU41092 - Permissions, Privileges, and Access Controls
CVE-2014-7828
CWE-264 Low
No
No
4.1.1-1.fc21 19.11.2014 SB2014111901
SB2014110603


Showing elements 21 - 40 out of 36