FreeIPA is an open-source identity and access management platform widely deployed in enterprise Linux environments, concentrated in a single product that serves as a critical authentication and authorization infrastructure component. Its vulnerability profile reflects the structural demands of a centralized identity system: recurring weaknesses cluster around sensitive information exposure, improper access control and authorization logic, resource exhaustion, and cross-site request forgery, with a moderate tendency toward serious outcomes across these classes. Defenders should treat FreeIPA disclosures as infrastructure-priority issues given the platform's central role in directory and authentication services; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freeipa over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14867HIGH A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used | Nov 27, 2019 | 8.8 | 29 | NO | NO |
CVE-2012-5631HIGH ipa 3.0 does not properly check server identity before sending credential containing cookies | Nov 25, 2019 | 8.8 | 26 | NO | NO |
CVE-2017-11191HIGH FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same use | Sep 28, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-12169HIGH It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potential | Jan 10, 2018 | 7.5 | 25 | NO | NO |
CVE-2024-2698HIGH A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fi | Jun 12, 2024 | 8.8 | 24 | NO | NO |
CVE-2015-5284CRITICAL ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable. | Sep 21, 2017 | 9.8 | 24 | NO | NO |
CVE-2016-5404MEDIUM The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging th | Sep 7, 2016 | 6.5 | 24 | NO | NO |
CVE-2016-5414HIGH FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services. | Jun 27, 2017 | 7.5 | 23 | NO | NO |
CVE-2016-9575MEDIUM Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. A | Mar 13, 2018 | 6.3 | 22 | NO | NO |
CVE-2019-10195MEDIUM A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged | Nov 27, 2019 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freeipa.
Media articles that mention a CVE ID that affects a product developed by Freeipa — matched by CVE ID, not by vendor name.