Known vulnerabilities in freeipa - page 2
Vendor:
Fedoraproject
Software:
freeipa
Software CPE:
cpe:2.3:o:fedoraproject:freeipa:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
36
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
4.13.2-1.fc43
4.13.2-1.fc44
4.13.2-1.fc45
4.13.1-16.fc45.2
4.13.1-7.fc43
4.13.1-12.fc44
4.13.1-16.fc45
4.12.5-1.fc41
4.12.5-1.fc42
4.7.4-1.fc29
4.8.3-1.fc30
4.8.3-1.fc31
4.6.4-2.fc27
4.4.3-2.fc25
4.4.3-1.fc25
4.3.2-4.fc24
4.3.2-3.fc24
4.4.2-2.fc25
4.3.2-2.fc25
4.3.2-2.fc24
4.2.4-2.fc23
4.2.2-1.fc23
4.1.4-1.fc21
4.1.4-1.fc22
4.1.1-2.fc21
4.1.1-1.fc21
4.11.1-2.fc39
4.10.3-2.fc38
4.12.2-3.fc40
4.12.2-7.fc41
4.10.0-6.fc37
4.9.6-3.fc33
4.9.6-4.fc34
4.9.7-4.fc35
4.9.7-4.fc36
4.9.2-4.fc32
4.9.2-4.fc33
4.9.2-4.fc34
4.12.1-1.fc39
4.12.1-1.fc40
4.11.1-4.fc40
4.11.1-4.fc41
4.10.3-1.fc38
4.11.1-1.fc39
4.11.1-1.fc40
Vulnerabilities (36)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU58098 - Improper Access Control CVE-2016-2124 |
CWE-284 | High | 4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 | 10.11.2021 |
SB2021111008 SB2021111201 SB2021112913 and 34 more |
||
| #VU58097 - Permissions, Privileges, and Access Controls CVE-2020-25717 |
CWE-264 | Medium | 4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 | 10.11.2021 |
SB2021111008 SB2021111201 SB2021112913 and 43 more |
||
| #VU58096 - Permissions, Privileges, and Access Controls CVE-2020-25718 |
CWE-264 | Medium | 4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 | 10.11.2021 |
SB2021111008 SB2021111201 SB2022012012 and 11 more |
||
| #VU58095 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2020-25719 |
CWE-362 | Low | 4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 | 10.11.2021 |
SB2021111008 SB2021111201 SB2021121644 and 17 more |
||
| #VU58094 - Improper Authentication CVE-2020-25721 |
CWE-287 | Medium | 4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 | 10.11.2021 |
SB2021111008 SB2021111201 SB2022012012 and 13 more |
||
| #VU58093 - Permissions, Privileges, and Access Controls CVE-2020-25722 |
CWE-264 | Medium | 4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 | 10.11.2021 |
SB2021111008 SB2021111201 SB2021113012 and 14 more |
||
| #VU58092 - Use After Free CVE-2021-3738 |
CWE-416 | Medium | 4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 | 10.11.2021 |
SB2021111008 SB2021111201 SB2022012012 and 11 more |
||
| #VU58091 - Improper input validation CVE-2021-23192 |
CWE-20 | Medium | 4.9.6-3.fc33, 4.9.6-4.fc34, 4.9.7-4.fc35, 4.9.7-4.fc36 | 10.11.2021 |
SB2021111008 SB2021111201 SB2021112914 and 19 more |
||
| #VU54105 - Exposure of sensitive information to an unauthorized actor CVE-2020-35518 |
CWE-200 | Medium | 4.9.2-4.fc32, 4.9.2-4.fc33, 4.9.2-4.fc34 | 15.06.2021 |
SB2021061502 SB2021061505 SB2021062118 and 12 more |
||
| #VU26103 - Improper input validation CVE-2019-14867 |
CWE-20 | High | 4.7.4-1.fc29, 4.8.3-1.fc30, 4.8.3-1.fc31 | 17.03.2020 |
SB2019112719 SB2019121718 SB2020040168 and 4 more |
||
| #VU26102 - Information Exposure Through Log Files CVE-2019-10195 |
CWE-532 | Low | 4.7.4-1.fc29, 4.8.3-1.fc30, 4.8.3-1.fc31 | 17.03.2020 |
SB2019112719 SB2019121718 SB2020040168 and 4 more |
||
| #VU36812 - Improper input validation CVE-2017-2590 |
CWE-20 | High | 4.4.3-2.fc25 | 27.07.2018 |
SB2018072718 SB2017022711 SB2017030214 |
||
| #VU37442 - Improper Authorization CVE-2016-9575 |
CWE-285 | Medium | 4.3.2-3.fc24, 4.3.2-4.fc24, 4.4.2-2.fc25, 4.4.3-1.fc25 | 13.03.2018 |
SB2018031342 SB2016121511 SB2016121512 and 3 more |
||
| #VU38415 - Credentials Management CVE-2016-7030 |
CWE-255 | Medium | 4.3.2-3.fc24, 4.3.2-4.fc24, 4.4.2-2.fc25, 4.4.3-1.fc25 | 28.08.2017 |
SB2017082811 SB2016121511 SB2016121512 and 3 more |
||
| #VU41054 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2014-7850 |
CWE-79 | Low | 4.1.1-2.fc21 | 28.11.2014 |
SB2014111901 SB2014112102 |
||
| #VU41092 - Permissions, Privileges, and Access Controls CVE-2014-7828 |
CWE-264 | Low | 4.1.1-1.fc21 | 19.11.2014 |
SB2014111901 SB2014110603 |
Showing elements 21 - 40 out of 36