CVE-2024-11029
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-11029 is a newly discovered vulnerability in the FreeIPA API audit. During the installation process, this flaw causes the FreeIPA API to inadvertently log the entire command line, including administrative user credentials, to the journal database. In extreme cases where the journal logs are centralized, unauthorized users with access to the logs can potentially gain improper access to the FreeIPA administrator credentials. This vulnerability poses a significant risk to system security and should be addressed promptly by updating to the latest FreeIPA version or implementing appropriate logging restrictions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.