Input validation error in FreeIPA - CVE-2024-1481

 

Input validation error in FreeIPA - CVE-2024-1481

Published: March 6, 2024


Vulnerability identifier: #VU87167
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-1481
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of Kerberos principal name in rpcserver before running kinit. A remote attacker can send a specially crated HTTP request to the "/sip/session/login_password" endpoint and perform a denial of service (DoS) attack.


Affected software

FreeIPA
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Fedora
python3-kdcproxy
python3-jwcrypto
python3-custodia
custodia
ipa-healthcheck-core
ipa-healthcheck
slapi-nis
python3-pyusb
python3-yubico
opendnssec
softhsm
softhsm-devel
ipa-common
python3-ipaclient
python3-ipalib
ipa-server-dns
python3-ipaserver
python3-ipatests
ipa-server-common
ipa-selinux
ipa-python-compat
ipa-client-common
ipa-server-trust-ad
ipa-server
ipa-client-samba
ipa-client-epn
ipa-client
freeipa
ipa (Red Hat package)
python3-qrcode
python3-qrcode-core
bind-dyndb-ldap

How to mitigate CVE-2024-1481

Install updates from vendor's website.

python3-kdcproxy - update to 0.4-5
python3-jwcrypto - update to 0.5.0-2
python3-custodia - update to 0.6.0-3
custodia - update to 0.6.0-3
ipa-healthcheck-core - update to 0.12-3
ipa-healthcheck - update to 0.12-3
slapi-nis - update to 0.60.0-4.0.1
python3-pyusb - update to 1.0.0-9.1
python3-yubico - update to 1.3.2-9.1
opendnssec - update to 2.1.7-1
softhsm - update to 2.6.0-5
softhsm-devel - update to 2.6.0-5
ipa-common - update to 4.9.13-10.0.1
python3-ipaclient - update to 4.9.13-10.0.1
python3-ipalib - update to 4.9.13-10.0.1
ipa-server-dns - update to 4.9.13-10.0.1
python3-ipaserver - update to 4.9.13-10.0.1
python3-ipatests - update to 4.9.13-10.0.1
ipa-server-common - update to 4.9.13-10.0.1
ipa-selinux - update to 4.9.13-10.0.1
ipa-python-compat - update to 4.9.13-10.0.1
ipa-client-common - update to 4.9.13-10.0.1
ipa-server-trust-ad - update to 4.9.13-10.0.1
ipa-server - update to 4.9.13-10.0.1
ipa-client-samba - update to 4.9.13-10.0.1
ipa-client-epn - update to 4.9.13-10.0.1
ipa-client - update to 4.9.13-10.0.1
freeipa - addressed in versions 4.10.3-2.fc38, 4.11.1-2.fc39, 4.11.1-4.fc40, 4.11.1-4.fc41
ipa (Red Hat package) - update to 4.11.0-9.el9_4
python3-qrcode - update to 5.1-12
python3-qrcode-core - update to 5.1-12
bind-dyndb-ldap - update to 11.6-5

External References

Related Security Bulletins