CVE-2023-5455
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
- Freeipa
- < 4.6.10, 4.9.14, 4.10.3, 4.11.0
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.6% (45th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2024-01-10
Workaround
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
No indexed exploits for CVE-2023-5455 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-5455 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.