Resource exhaustion in FreeIPA - CVE-2020-1722
Published: April 27, 2020 / Updated: September 30, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources while trying to hash an overly long password string (more than 1 million characters). A remote attacker can send a specially crafted HTTP request, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
ipa (Red Hat package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
How to mitigate CVE-2020-1722
ipa (Red Hat package) - update to 4.6.8-5.el7