CVE-2008-3274
12.09.2008, 16:56
The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, which allows remote attackers to obtain the Kerberos master key via an anonymous LDAP query.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | enterprise_ipa | 1.0.0 |
redhat | freeipa | 𝑥 ≤ 1.1.0 |
redhat | freeipa | 0.99 |
redhat | freeipa | 1.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References