Junglewise Threat Intelligence

PYSEC-2014-103 - The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing at

Severity: info · Published 2014-05-29

Technologies: ipa (PyPI). Vendors: PyPI.

Executive brief

The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.

Affected products

  • PyPI ipa

Related threats