AI analysis
FreeIPA's self-managed OTP token access-control rule (ACI) permits anonymous, unauthenticated LDAP access and does not restrict which attributes may be added alongside a token entry. Chained with a separate flaw in the underlying directory server's ACI evaluation (tracked in a different CVE), a remote, unauthenticated LDAP client can create an attacker-controlled Kerberos principal and have it added to the FreeIPA administrators group. The attacker thereby obtains genuine administrator-group membership and can perform administrative operations against the directory and, on deployments with SID support, against other Identity Management services. Any organization running FreeIPA, including Red Hat Enterprise Linux Identity Management deployments, is affected; the available data does not specify affected or fixed version ranges. No public proof of concept, KEV listing, or known in-the-wild exploitation exists, and EPSS estimates a 0.5% probability of exploitation within 30 days.
What to do: Apply the FreeIPA update from the Red Hat security advisory as soon as a fixed package is released (the data here does not list fixed versions), and also patch the underlying directory server for the companion ACI-evaluation flaw this issue is chained with. Until patched, restrict unauthenticated network access to LDAP on FreeIPA servers (ports 389/636) to trusted networks only, and audit the administrators group and directory audit logs for unexpected principals or recently created Kerberos entries.
Affected
| Red Hat / FreeIPA project FreeIPA (including its use as Red Hat Enterprise Linux Identity Management) | — |
Estimated exposure
moderateOn the order of tens of thousands of FreeIPA servers across thousands of enterprise deployments, with only a fraction exposed to unauthenticated LDAP; not… — FreeIPA is the bundled Identity Management solution for RHEL/Fedora-style enterprise environments and is typically deployed as small internal server clusters rather than internet-facing services, implying an installed base in the tens of…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.