The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freeipa | Redhat | 3.0.0 (including) | 3.0.0 (including) |
Freeipa | Redhat | 3.0.1 (including) | 3.0.1 (including) |
Freeipa | Redhat | 3.0.2 (including) | 3.0.2 (including) |
Freeipa | Redhat | 3.1.1 (including) | 3.1.1 (including) |
Freeipa | Ubuntu | upstream | * |