[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255227

 
 

909

 
 

198741

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2024-2698Date: (C)2024-06-15   (M)2024-06-17


A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed_to_delegate() function: If the target service argument is NULL, then it means the KDC is probing for general constrained delegation rules and not checking a specific S4U2Proxy request. In FreeIPA 4.11.0, the behavior of ipadb_match_acl() was modified to match the changes from upstream MIT Kerberos 1.20. However, a mistake resulting in this mechanism applies in cases where the target service argument is set AND where it is unset. This results in S4U2Proxy requests being accepted regardless of whether or not there is a matching service delegation rule.

Reference:
RHBZ#2270353
RHSA-2024:3754
RHSA-2024:3755
RHSA-2024:3757
RHSA-2024:3759
https://access.redhat.com/security/cve/CVE-2024-2698
https://www.freeipa.org/release-notes/4-12-1.html

CWE    1
CWE-284
OVAL    2
oval:org.secpod.oval:def:509437
oval:org.secpod.oval:def:509429
XCCDF    1

© SecPod Technologies