Back

HIGH

ipa: Session reuse to unlock the locked user

Published Sep 27, 2017

Description

FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern

Affected products

Remediation

Red Hat statement

This security issue does not exist in IPA / FreeIPA. FreeIPA server correctly rejects the HTTP request for "user_unlock" method with 401 Unauthorized HTTP code when the attacker tries to reuse an older browser session. Therefore, we do not consider this report as a valid security concern. We have submitted a request to MITRE to reject this CVE ID.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 27, 2017
Updated Aug 5, 2024
Reserved Jul 12, 2017
CISA Vulnrichment
Updated Apr 22, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 27, 2017