Skip to main content

Exposure of Sensitive System Information to an Unauthorized Control Sphere

CVE-2024-11029

Severity Medium
Score 5.5/10

Summary

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to `journalctl`. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials. This issue has been fixed in version 4.12.3.

  • LOW
  • LOCAL
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere

The application does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the application does.

Advisory Timeline

  • Published