The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade freeipa
to version 4.12.4 or higher.
Affected versions of this package are vulnerable to Insufficient Granularity of Access Control via the lack of uniqueness enforcement on the krbCanonicalName
attribute. An attacker can gain full administrative privileges across the domain by crafting a principal with the same canonical name as the domain administrator and obtaining a Kerberos service ticket containing PAC data. This enables unrestricted access to sensitive systems and data, including user management, policy manipulation, and credential extraction.