Flaw in FreeIPA API Audit Leads to Credential Exposure
CVE-2024-11029
5.5MEDIUM
Key Information:
- Vendor
- Red Hat
- Vendor
- CVE Published:
- 15 January 2025
Summary
A significant flaw was identified in the FreeIPA API audit process where it logs entire FreeIPA command lines to journalctl. This flaw leads to unintended leakage of sensitive information, particularly administrative user credentials, during the installation phase. If the journal log is centralized, individuals with access to these logs could improperly obtain the administrator's password, posing a serious security risk. Proper remediation and patching are essential to protect administrative accounts and sensitive data.
Affected Version(s)
Red Hat Enterprise Linux 9 0:4.12.2-1.el9_5.3
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved