Improper Authorization in FreeIPA - CVE-2024-2698
Published: June 19, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to an error in ipadb_match_acl() within the initial implementation of MS-SFU by MIT Kerberos, which was missing a condition for granting the “forwardable” flag on S4U2Self tickets. This results in S4U2Proxy requests to be accepted regardless of the fact there is a matching service delegation rule or not.
Note, this vulnerability does not affect default FreeIPA deployments because the services which have delegation rules defined are on IPA servers themselves. Services having RBCD (resource-based constrained delegation) rules are not affected by this vulnerability either.
Affected software
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python3-kdcproxy
python3-jwcrypto
python3-custodia
custodia
ipa-healthcheck-core
ipa-healthcheck
slapi-nis
python3-pyusb
python3-yubico
opendnssec
softhsm
softhsm-devel
ipa-server-common
python3-ipatests
python3-ipaserver
python3-ipalib
python3-ipaclient
ipa-server-dns
ipa-server-trust-ad
ipa-selinux
ipa-python-compat
ipa-client
ipa-client-epn
ipa-common
ipa-client-common
ipa-client-samba
ipa-server
ipa (Red Hat package)
freeipa
python3-qrcode
python3-qrcode-core
bind-dyndb-ldap
How to mitigate CVE-2024-2698
python3-kdcproxy - update to 0.4-5
python3-jwcrypto - update to 0.5.0-2
python3-custodia - update to 0.6.0-3
custodia - update to 0.6.0-3
ipa-healthcheck-core - update to 0.12-3
ipa-healthcheck - update to 0.12-3
slapi-nis - update to 0.60.0-4.0.1
python3-pyusb - update to 1.0.0-9.1
python3-yubico - update to 1.3.2-9.1
opendnssec - update to 2.1.7-1
softhsm - update to 2.6.0-5
softhsm-devel - update to 2.6.0-5
ipa-server-common - update to 4.9.13-10.0.1
python3-ipatests - update to 4.9.13-10.0.1
python3-ipaserver - update to 4.9.13-10.0.1
python3-ipalib - update to 4.9.13-10.0.1
python3-ipaclient - update to 4.9.13-10.0.1
ipa-server-dns - update to 4.9.13-10.0.1
ipa-server-trust-ad - update to 4.9.13-10.0.1
ipa-selinux - update to 4.9.13-10.0.1
ipa-python-compat - update to 4.9.13-10.0.1
ipa-client - update to 4.9.13-10.0.1
ipa-client-epn - update to 4.9.13-10.0.1
ipa-common - update to 4.9.13-10.0.1
ipa-client-common - update to 4.9.13-10.0.1
ipa-client-samba - update to 4.9.13-10.0.1
ipa-server - update to 4.9.13-10.0.1
ipa (Red Hat package) - addressed in versions 4.10.1-12.el9_2.2, 4.11.0-15.el9_4
freeipa - addressed in versions 4.12.1-1.fc39, 4.12.1-1.fc40
python3-qrcode - update to 5.1-12
python3-qrcode-core - update to 5.1-12
bind-dyndb-ldap - update to 11.6-5
External References
Related Security Bulletins
- Multiple vulnerabilities in FreeIPA
- Red Hat Enterprise Linux 9 update for ipa
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Red Hat Enterprise Linux 9 update for ipa
- Red Hat Enterprise Linux8 update for the idm:DL1 module
- Fedora 40 update for freeipa
- Fedora 39 update for freeipa
- Anolis OS update for idm:DL1 module