FreeIPA의 결함으로 익명 클라이언트가 재사용 가능한 관리자 자격증명을 생성할 수 있음.
FreeIPA에서 발견된 결함으로 인해 로그인을 한 번도 하지 않은 클라이언트가 원하는 Kerberos ID를 생성하고 관리 그룹에 포함될 수 있습니다. Red Hat에 따르면 이 공격은 389 Directory Server 데이터베이스 내에서 두 번째 결함이 필요합니다. 이는 Linux 도메인에서의 인증 관리를 심각하게 위협할 수 있는 문제입니다.
A flaw in FreeIPA allows anonymous clients to create reusable admin credentials.
A flaw in FreeIPA enables a client that has never logged in to create a Kerberos identity of its choosing and gain access to the administrators group. According to Red Hat, this attack requires a second flaw within the 389 Directory Server database. This issue poses a significant threat to authentication management across Linux domains.