Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freeipa

First CVE: Nov 19, 2014Active for: 12 yearsTotal CVEs: 19
39.5
VTI Score
Medium

FreeIPA is an open-source identity and access management platform widely deployed in enterprise Linux environments, concentrated in a single product that serves as a critical authentication and authorization infrastructure component. Its vulnerability profile reflects the structural demands of a centralized identity system: recurring weaknesses cluster around sensitive information exposure, improper access control and authorization logic, resource exhaustion, and cross-site request forgery, with a moderate tendency toward serious outcomes across these classes. Defenders should treat FreeIPA disclosures as infrastructure-priority issues given the platform's central role in directory and authentication services; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Freeipa over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2014
11 years ago
Most Recent CVE
Jun 12, 2024
772 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-14867HIGH
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used
Nov 27, 20198.829NONO
CVE-2012-5631HIGH
ipa 3.0 does not properly check server identity before sending credential containing cookies
Nov 25, 20198.826NONO
CVE-2017-11191HIGH
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same use
Sep 28, 20178.826NONO
CVE-2017-12169HIGH
It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potential
Jan 10, 20187.525NONO
CVE-2024-2698HIGH
A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fi
Jun 12, 20248.824NONO
CVE-2015-5284CRITICAL
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
Sep 21, 20179.824NONO
CVE-2016-5404MEDIUM
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging th
Sep 7, 20166.524NONO
CVE-2016-5414HIGH
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
Jun 27, 20177.523NONO
CVE-2016-9575MEDIUM
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. A
Mar 13, 20186.322NONO
CVE-2019-10195MEDIUM
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged
Nov 27, 20196.521NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
42%
47%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (5.3%)
Network15 (78.9%)
Unknown3 (15.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (78.9%)
High1 (5.3%)
Unknown3 (15.8%)
User Interaction
None12 (63.2%)
Unknown3 (15.8%)
Required4 (21.1%)
Privileges Required
Low6 (31.6%)
High1 (5.3%)
None9 (47.4%)
Unknown3 (15.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freeipa.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freeipa — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freeipa's Products

View all 2 CNAs →

Top CWEs