Flaw in FreeIPA API Audit Leads to Credential Exposure
CVE-2024-11029
5.5MEDIUM
Key Information:
- Vendor
- CVE Published:
- 15 January 2025
What is CVE-2024-11029?
A significant flaw was identified in the FreeIPA API audit process where it logs entire FreeIPA command lines to journalctl. This flaw leads to unintended leakage of sensitive information, particularly administrative user credentials, during the installation phase. If the journal log is centralized, individuals with access to these logs could improperly obtain the administrator's password, posing a serious security risk. Proper remediation and patching are essential to protect administrative accounts and sensitive data.