Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FreeIPA 不安全CA证书处理漏洞
Vulnerability Description
Red Hat FreeIPA是美国红帽(Red Hat)公司的一套集成的安全信息管理解决方案。该方案对Linux和Unix计算机网络提供了易于管理的身份、策略和审计(IPA)套件。 FreeIPA 2.x版本和3.1.2之前的3.x版本中的客户端中存在漏洞,该漏洞源于程序没有从服务器正确获得Certification Authority (CA)证书。通过特制的证书,中间人攻击者可利用该漏洞欺骗加入过程。
CVSS Information
N/A
Vulnerability Type
N/A