CVE-2024-1481
A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 1.1% (64th percentile)
- Weakness
- CWE-20
- NVD status
- Deferred
- Published
- 2024-04-10
Workaround
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
CVE-2024-1481 at NVD
1 known exploit for CVE-2024-1481
Proof-of-concept code and exploit modules indexed by Sploitus