Improper Authorization in FreeIPA - CVE-2024-2698

 

Improper Authorization in FreeIPA - CVE-2024-2698

Published: June 19, 2024


Vulnerability identifier: #VU92247
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-2698
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to an error in ipadb_match_acl() within the initial implementation of MS-SFU by MIT Kerberos, which was missing a condition for granting the “forwardable” flag on S4U2Self tickets. This results in S4U2Proxy requests to be accepted regardless of the fact there is a matching service delegation rule or not.

Note, this vulnerability does not affect default FreeIPA deployments because the services which have delegation rules defined are on IPA servers themselves. Services having RBCD (resource-based constrained delegation) rules are not affected by this vulnerability either.


Affected software

FreeIPA
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python3-kdcproxy
python3-jwcrypto
python3-custodia
custodia
ipa-healthcheck-core
ipa-healthcheck
slapi-nis
python3-pyusb
python3-yubico
opendnssec
softhsm
softhsm-devel
ipa-server-common
python3-ipatests
python3-ipaserver
python3-ipalib
python3-ipaclient
ipa-server-dns
ipa-server-trust-ad
ipa-selinux
ipa-python-compat
ipa-client
ipa-client-epn
ipa-common
ipa-client-common
ipa-client-samba
ipa-server
ipa (Red Hat package)
freeipa
python3-qrcode
python3-qrcode-core
bind-dyndb-ldap

How to mitigate CVE-2024-2698

Install updates from vendor's website.

FreeIPA - addressed in versions 4.11.2, 4.12.1
python3-kdcproxy - update to 0.4-5
python3-jwcrypto - update to 0.5.0-2
python3-custodia - update to 0.6.0-3
custodia - update to 0.6.0-3
ipa-healthcheck-core - update to 0.12-3
ipa-healthcheck - update to 0.12-3
slapi-nis - update to 0.60.0-4.0.1
python3-pyusb - update to 1.0.0-9.1
python3-yubico - update to 1.3.2-9.1
opendnssec - update to 2.1.7-1
softhsm - update to 2.6.0-5
softhsm-devel - update to 2.6.0-5
ipa-server-common - update to 4.9.13-10.0.1
python3-ipatests - update to 4.9.13-10.0.1
python3-ipaserver - update to 4.9.13-10.0.1
python3-ipalib - update to 4.9.13-10.0.1
python3-ipaclient - update to 4.9.13-10.0.1
ipa-server-dns - update to 4.9.13-10.0.1
ipa-server-trust-ad - update to 4.9.13-10.0.1
ipa-selinux - update to 4.9.13-10.0.1
ipa-python-compat - update to 4.9.13-10.0.1
ipa-client - update to 4.9.13-10.0.1
ipa-client-epn - update to 4.9.13-10.0.1
ipa-common - update to 4.9.13-10.0.1
ipa-client-common - update to 4.9.13-10.0.1
ipa-client-samba - update to 4.9.13-10.0.1
ipa-server - update to 4.9.13-10.0.1
ipa (Red Hat package) - addressed in versions 4.10.1-12.el9_2.2, 4.11.0-15.el9_4
freeipa - addressed in versions 4.12.1-1.fc39, 4.12.1-1.fc40
python3-qrcode - update to 5.1-12
python3-qrcode-core - update to 5.1-12
bind-dyndb-ldap - update to 11.6-5

External References

Related Security Bulletins