Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat FreeIPA 权限许可和访问控制漏洞
Vulnerability Description
Red Hat FreeIPA是美国红帽(Red Hat)公司的一套集成的安全信息管理解决方案。该方案对Linux和Unix计算机网络提供了易于管理的身份、策略和审计(IPA)套件。 Red Hat FreeIPA 4.0.5之前4.0.x版本和4.1.1版本中存在安全漏洞。当程序启用2FA时,远程攻击者可借助特制的OTP令牌利用该漏洞绕过two-factor身份验证的密码请求。
CVSS Information
N/A
Vulnerability Type
N/A