FreeIPA CVE-2017-12169 Information Disclosure Vulnerability
BID:102136
CVE-2017-12169 |Info
FreeIPA CVE-2017-12169 Information Disclosure Vulnerability
| Bugtraq ID: | 102136 |
| Class: | Design Error |
| CVE: |
CVE-2017-12169 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2017 12:00AM |
| Updated: | Dec 19 2017 10:01PM |
| Credit: | Rob Crittenden |
| Vulnerable: |
FreeIPA FreeIPA 4.4.4 |
| Not Vulnerable: | |
Discussion
FreeIPA CVE-2017-12169 Information Disclosure Vulnerability
FreeIPA is prone to a information-disclosure vulnerability.
The attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
FreeIPA is prone to a information-disclosure vulnerability.
The attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
Exploit / POC
FreeIPA CVE-2017-12169 Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
FreeIPA CVE-2017-12169 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
FreeIPA CVE-2017-12169 Information Disclosure Vulnerability
References:
References:
- Password hash disclosure via 'System: Read Stage Users' permission (bugzilla)
- CVE-2017-12169 (redhat)
- freeipa home page (freeipa)
- Password hash disclosure via 'System: Read Stage Users' permission (redhat)