← Back

CVE-2023-5455

nvd nist
Published: Jan 10, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

Affected (59)

1 product
Freeipa
1 product
Fedora
19 products
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Freeipa
Before 4.6.10
From 4.10.0 to 4.10.3
From 4.7.0 to 4.9.14
Version 4.11.0
Version 4.11.0 beta1
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 38
Version 39
Version 40
Configuration C
51 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Redhat
Version 7.0
Version 8.0
Version 8.0
Version 8.4
Version 9.0
Version 7.0
Redhat
Version 8.6
Version 8.6
Version 8.8
Version 9.0
Version 9.2
Redhat
Version 8.8
Version 9.0
Version 9.2
Redhat
Version 7.0
Version 8.0
Version 9.0
Redhat
Version 8.6
Version 8.8
Version 9.0
Version 9.2
Version 7.0
Redhat
Version 7.0
Version 8.0
Version 9.0
Redhat
Version 8.6
Version 8.8
Version 9.0
Version 9.2
Version 7.0
Redhat
Version 9.0
Version 9.2
Redhat
Version 8.2
Version 8.4
Version 8.6
Version 9.2
Version 9.2
Redhat
Version 8.2
Version 8.4
Version 8.6
Redhat
Version 8.2
Version 8.4
Version 8.6
Redhat
Version 8.2
Version 8.6
Version 9.0
Version 9.2
Redhat
Version 9.0
Version 9.2
Version 7.0

References (33)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Release Notes
Source: secalert@redhat.com
Release Notes
Source: secalert@redhat.com
Release Notes
Source: secalert@redhat.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes

Timeline

No history available yet.