CVE-2023-5455

NameCVE-2023-5455
DescriptionA Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1060415

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freeipa (PTS)buster (security), buster, buster (lts)4.7.2-3+deb10u1vulnerable
bookworm4.9.11-1vulnerable
sid4.11.1-2.1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freeipasource(unstable)(unfixed)unimportant1060415

Notes

https://www.freeipa.org/release-notes/4-10-3.html#highlights-in-4-10-3
https://www.freeipa.org/release-notes/4-9-14.html#highlights-in-4-9-14
Fixed by: https://pagure.io/freeipa/c/363fd5de98e883800ac08b2760e8c3150783e7e2 (release-4-10-3)
Fixed by: https://pagure.io/freeipa/c/9b1a65fe3936c4d3fe237775e54f0249b740f23e (release-4-9-14)
freeipa-server packages only built with 4.10.2-2+exp1/experimental

Search for package or bug name: Reporting problems