Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2024-11029
Summary
A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to `journalctl`. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials. This issue has been fixed in version 4.12.3.
- LOW
- LOCAL
- NONE
- UNCHANGED
- NONE
- LOW
- HIGH
- NONE
CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
The application does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the application does.
Advisory Timeline
- Published