Unrestricted Access to Cross-Realm Kerberos Trust Key in FreeIPA 3.0
CVE-2013-0199 · MEDIUM Severity
AV:N/AC:L/AU:N/C:P/I:N/A:N
The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.
Learn more about our Web Application Penetration Testing UK.