Insufficient Granularity of Access Control in FreeIPA - CVE-2025-7493

 

Insufficient Granularity of Access Control in FreeIPA - CVE-2025-7493

Published: October 1, 2025


Vulnerability identifier: #VU116216
CSH Severity: Medium
CVSS v4: 6.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2025-7493
CWE-ID: CWE-1220
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges from host to domain administrator.

The vulnerability exists due the application does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. A remote user can perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.


Affected software

FreeIPA
Netezza Appliance
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python3-kdcproxy
python3-jwcrypto
python3-custodia
custodia
ipa-healthcheck-core
ipa-healthcheck
slapi-nis
python3-pyusb
python3-yubico
opendnssec
softhsm
softhsm-devel
ipa (Red Hat package)
ipa-server-trust-ad
python2-ipaserver
python2-ipalib
python2-ipaclient
ipa-server-dns
ipa-server-common
ipa-client
ipa-python-compat
ipa-common
ipa-server
ipa-client-common
python3-ipatests
python3-ipaserver
python3-ipaclient
ipa-client-epn
ipa-client-samba
ipa-selinux
python3-ipalib
freeipa
python3-qrcode-core
python3-qrcode
bind-dyndb-ldap

How to mitigate CVE-2025-7493

Install updates from vendor's website.

FreeIPA - update to 4.12.5
Netezza Appliance - update to 1.0.1.0 fp278500
python3-kdcproxy - update to 0.4-5
python3-jwcrypto - update to 0.5.0-2
python3-custodia - update to 0.6.0-3
custodia - update to 0.6.0-3
ipa-healthcheck-core - update to 0.12-6
ipa-healthcheck - update to 0.12-6
slapi-nis - update to 0.60.0-4.0.1
python3-pyusb - update to 1.0.0-9.1
python3-yubico - update to 1.3.2-9.1
opendnssec - update to 2.1.7-2
softhsm - update to 2.6.0-5
softhsm-devel - update to 2.6.0-5
ipa (Red Hat package) - addressed in versions 4.6.8-5.el7_9.23, 4.9.8-11.el9_0.5, 4.10.1-12.el9_2.6, 4.11.0-15.el9_4.7, 4.12.2-14.el9_6.5, 4.12.2-15.el10_0.4
ipa-server-trust-ad - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
python2-ipaserver - update to 4.6.8-5.0.1
python2-ipalib - update to 4.6.8-5.0.1
python2-ipaclient - update to 4.6.8-5.0.1
ipa-server-dns - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-server-common - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-client - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-python-compat - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-common - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-server - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-client-common - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
python3-ipatests - update to 4.9.13-20.0.1
python3-ipaserver - update to 4.9.13-20.0.1
python3-ipaclient - update to 4.9.13-20.0.1
ipa-client-epn - update to 4.9.13-20.0.1
ipa-client-samba - update to 4.9.13-20.0.1
ipa-selinux - update to 4.9.13-20.0.1
python3-ipalib - update to 4.9.13-20.0.1
freeipa - addressed in versions 4.12.5-1.fc41, 4.12.5-1.fc42
python3-qrcode-core - update to 5.3-1
python3-qrcode - update to 5.3-1
bind-dyndb-ldap - update to 11.6-6

External References

Related Security Bulletins