vendor
freeipa
Severity
Its products
Being told
The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.
Every thing
| ipa: FreeIPA: Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read CVE-2026-73198 | Severity high |
| ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read CVE-2026-73197 | Severity high |
| freeipa: ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes CVE-2026-19550 | Severity high |
| ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore CVE-2026-13097 | Severity high |
| FreeIPA: idm: ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships CVE-2026-11861 | Severity high |