Junglewise Threat Intelligence
CVE-2012-5484: PYSEC-2013-38 - The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which
CVE-2012-5484 · Severity: info · Published 2013-01-27
Technologies: freeipa (PyPI), ipa (PyPI). Vendors: PyPI.
Executive brief
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
Related threats
- PYSEC-2026-636 - Code injection in FreeIPA
- PYSEC-2019-98 - A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way th
- PYSEC-2019-92 - A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way th
- PYSEC-2019-22 - A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way th
- PYSEC-2014-101 - FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the tw