FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freeipa | Freeipa | 4.6.0 (including) | 4.6.0 (including) |
Red Hat Enterprise Linux 7 | RedHat | ipa-0:4.4.0-14.el7_3.1.1 | * |
Freeipa | Ubuntu | artful | * |
Freeipa | Ubuntu | esm-apps/xenial | * |
Freeipa | Ubuntu | precise | * |
Freeipa | Ubuntu | trusty | * |
Freeipa | Ubuntu | trusty/esm | * |
Freeipa | Ubuntu | upstream | * |
Freeipa | Ubuntu | xenial | * |
Freeipa | Ubuntu | yakkety | * |
Freeipa | Ubuntu | zesty | * |