Back

HIGH

ipa: Password hash disclosure via 'System: Read Stage Users' permission

Published Jan 10, 2018

Description

It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potentially use this flaw to disclose the password hashes belonging to Stage Users. This security issue does not result in disclosure of password hashes belonging to active standard users. NOTE: some developers feel that this report is a suggestion for a design change to Stage User activation, not a statement of a vulnerability.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 10, 2018
Updated Aug 5, 2024
Reserved Aug 1, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 6, 2017