CVE Database
/

CVE-2023-5455

Back to search

CVE-2023-5455

Published: Jan 10, 2024

Modified: Mar 18, 2026

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

VendorProductVersions

Red Hat

Red Hat Enterprise Linux 7

unaffected
0:4.6.8-5.el7_9.16 - < *

Red Hat

Red Hat Enterprise Linux 8

unaffected
8090020231201152514.3387e3d0 - < *

Red Hat

Red Hat Enterprise Linux 8.2 Advanced Update Support

unaffected
8020020231123154806.792f4060 - < *

Red Hat

Red Hat Enterprise Linux 8.2 Telecommunications Update Service

unaffected
8020020231123154806.792f4060 - < *

Red Hat

Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions

unaffected
8020020231123154806.792f4060 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

unaffected
8040020231123154610.5b01ab7e - < *

Red Hat

Red Hat Enterprise Linux 8.4 Telecommunications Update Service

unaffected
8040020231123154610.5b01ab7e - < *

Red Hat

Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions

unaffected
8040020231123154610.5b01ab7e - < *

Red Hat

Red Hat Enterprise Linux 8.6 Extended Update Support

unaffected
8060020231208020207.ada582f1 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Extended Update Support

unaffected
8080020231201153604.b0a6ceea - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
0:4.10.2-5.el9_3 - < *

Red Hat

Red Hat Enterprise Linux 9.0 Extended Update Support

unaffected
0:4.9.8-9.el9_0 - < *

Red Hat

Red Hat Enterprise Linux 9.2 Extended Update Support

unaffected
0:4.10.1-10.el9_2 - < *

Red Hat

Red Hat Enterprise Linux 6

All versions

Red Hat

Red Hat Enterprise Linux 8

All versions

Red Hat

Red Hat Enterprise Linux 8

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

None

Integrity

High

Availability

None

References

RHSA-2024:0137
vendor-advisory
x_refsource_REDHAT
RHSA-2024:0138
vendor-advisory
x_refsource_REDHAT
RHSA-2024:0139
vendor-advisory
x_refsource_REDHAT
RHSA-2024:0140
vendor-advisory
x_refsource_REDHAT
RHSA-2024:0141
vendor-advisory
x_refsource_REDHAT
RHSA-2024:0142
vendor-advisory
x_refsource_REDHAT
RHSA-2024:0143
vendor-advisory
x_refsource_REDHAT
RHSA-2024:0144
vendor-advisory
x_refsource_REDHAT
RHSA-2024:0145
vendor-advisory
x_refsource_REDHAT
RHBZ#2242828
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now