CVE-2024-11029

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 15, 2025
CWE ID 497

Summary

CVE-2024-11029 is a newly discovered vulnerability in the FreeIPA API audit. During the installation process, this flaw causes the FreeIPA API to inadvertently log the entire command line, including administrative user credentials, to the journal database. In extreme cases where the journal logs are centralized, unauthorized users with access to the logs can potentially gain improper access to the FreeIPA administrator credentials. This vulnerability poses a significant risk to system security and should be addressed promptly by updating to the latest FreeIPA version or implementing appropriate logging restrictions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share