Unrestricted Access to Cross-Realm Kerberos Trust Key in FreeIPA 3.0

Unrestricted Access to Cross-Realm Kerberos Trust Key in FreeIPA 3.0

CVE-2013-0199 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.

Learn more about our Web Application Penetration Testing UK.