CVE-2024-1481

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.
Configurations

No configuration.

History

21 Nov 2024, 08:50

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2024:2147 - () https://access.redhat.com/errata/RHSA-2024:2147 -
References () https://access.redhat.com/errata/RHSA-2024:3044 - () https://access.redhat.com/errata/RHSA-2024:3044 -
References () https://access.redhat.com/security/cve/CVE-2024-1481 - () https://access.redhat.com/security/cve/CVE-2024-1481 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2262169 - () https://bugzilla.redhat.com/show_bug.cgi?id=2262169 -

22 May 2024, 17:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:3044 -

30 Apr 2024, 14:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2147 -
Summary
  • (es) Se encontró una falla en FreeIPA. Este problema puede permitir a un atacante remoto crear una solicitud HTTP con parámetros que pueden interpretarse como argumentos de comando para kinit en el servidor FreeIPA, lo que puede provocar una denegación de servicio.

10 Apr 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 21:15

Updated : 2024-11-21 08:50


NVD link : CVE-2024-1481

Mitre link : CVE-2024-1481

CVE.ORG link : CVE-2024-1481


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation