VDB
BDU%3A2024-02540
BDU%3A2024-02540
PUBLISHED
CVSS 6.5 MEDIUM
Уязвимость компонента login_password сервера FreeIpa, позволяющая нарушителю осуществить CSRF-атаку
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | 8040020231123154610.5b01ab7e |
| Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | 8040020231123154610.5b01ab7e |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | 0:4.10.1-10.el9_2 |
| Red Hat | Red Hat Enterprise Linux 7 | 0:4.6.8-5.el7_9.16 |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 0:4.9.8-9.el9_0 |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | 8060020231208020207.ada582f1 |
| Red Hat | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | 8020020231123154806.792f4060 |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 8040020231123154610.5b01ab7e |
| ООО «Ред Софт», ООО «РусБИТех-Астра», АО «ИВК», Сообщество свободного программного обеспечения | РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Альт 8 СП (запись в едином реестре российских программ №4305), АЛЬТ СП 10, FreeIPA | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | 8080020231201153604.b0a6ceea |
| Red Hat | Red Hat Enterprise Linux 9 | 0:4.10.2-5.el9_3 |
| Red Hat | Red Hat Enterprise Linux 8 | 8090020231201152514.3387e3d0 |
| Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | 8020020231123154806.792f4060 |
| Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | 8020020231123154806.792f4060 |
Timeline
- Jan 10, 2024 CVE Published
- Jan 10, 2024 PoC Published
- Jan 10, 2024 PoC Published
- Jan 28, 2024 PoC Published
- Oct 29, 2025 CVE Updated
- May 29, 2026 Distribution Patch
- May 29, 2026 Distribution Patch
- May 29, 2026 Distribution Patch
- May 29, 2026 Distribution Patch
- May 29, 2026 Distribution Patch
- May 29, 2026 Distribution Patch
- May 29, 2026 Distribution Patch
References
- https://redos.red-soft.ru/support/secure/ url
- https://www.freeipa.org/release-notes/4-10-3.html url
- https://www.freeipa.org/release-notes/4-11-1.html url
- https://www.freeipa.org/release-notes/4-6-10.html url
- https://www.freeipa.org/release-notes/4-9-14.html url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-0114SE18MD url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- RHSA-2024:0137 vendor-advisory
- RHSA-2024:0138 vendor-advisory
- RHSA-2024:0139 vendor-advisory
- RHSA-2024:0140 vendor-advisory
- RHSA-2024:0141 vendor-advisory
- RHSA-2024:0142 vendor-advisory
- RHSA-2024:0143 vendor-advisory
- RHSA-2024:0144 vendor-advisory
- RHSA-2024:0145 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-5455 vdb
…and 4 more