Exposure of System Data to an Unauthorized Control Sphere Affecting freeipa package, versions *


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN12-FREEIPA-8642821
  • published17 Jan 2025
  • disclosed15 Jan 2025

Introduced: 15 Jan 2025

NewCVE-2024-11029  (opens in a new tab)
CWE-497  (opens in a new tab)

How to fix?

There is no fixed version for Debian:12 freeipa.

NVD Description

Note: Versions mentioned in the description apply only to the upstream freeipa package and not the freeipa package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials.

CVSS Scores

version 3.1