This project will be discontinued after December 13, 2021. [more]
Product:
Enterprise_linux_server_for_ibm_z_systems
(Redhat)
Repositories
Unknown:
This might be proprietary software.
#Vulnerabilities
1
Date
Id
Summary
Products
Score
Patch
Annotated
2024-01-10
CVE-2023-5455
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie...