CyberSecurity News
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
AI summary
A vulnerability in FreeIPA allows an anonymous client to create a Kerberos identity and gain administrator privileges. This is possible because the client can create an identity of its choice in the directory and be added to the administrators group. FreeIPA is a system used for managing identities and login access across a Linux domain, storing identities in a 389 Directory Server database. The attack relies on a second vulnerability in the 389 Directory Server database software. Red Hat has acknowledged the flaw in FreeIPA. The vulnerability can be exploited by a client that has never previously logged in.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

