freeipa
Dummy package for FreeIPA
Activity
- Latest release
- 7mo ago
- Total releases
- 28
- Cadence
- ~2 months
- Last 12 months
- 1
Details
- License
- GPL-3.0
- First release
- Nov 09, 2016
| Version | Released | |
|---|---|---|
4.13.1
minor
|
4.13.1
minor
Dependencies (1)
|
|
4.12.2
minor
|
4.12.2
minor
Dependencies (1)
|
|
4.9.12
minor
|
4.9.12
minor
Dependencies (1)
|
|
4.10.2
minor
|
4.10.2
minor
Dependencies (1)
|
|
4.8.9
patch
|
4.8.9
patch
Dependencies (1)
|
|
4.8.7
patch
|
4.8.7
patch
Dependencies (1)
|
|
4.7.5
patch
|
4.7.5
patch
Dependencies (1)
|
|
4.8.6
patch
|
4.8.6
patch
Dependencies (1)
|
|
4.8.5
patch
|
4.8.5
patch
Dependencies (1)
|
|
4.7.4
patch
|
4.7.4
patch
Dependencies (1)
|
|
4.6.7
patch
|
4.6.7
patch
Dependencies (1)
|
|
4.8.3
patch
|
4.8.3
patch
Dependencies (1)
|
|
4.8.2
patch
2 CVEs
CVE-2019-14867
PYSEC-2026-636
GHSA-7hpj-hfcr-5qwm
PYSEC-2019-28
Jul 02, 2026
Code injection in FreeIPA
Critical
Network
Low
None
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. Affected versions
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.8.2
patch
Dependencies (1)
|
|
4.8.1
patch
2 CVEs
CVE-2019-14867
PYSEC-2026-636
GHSA-7hpj-hfcr-5qwm
PYSEC-2019-28
Jul 02, 2026
Code injection in FreeIPA
Critical
Network
Low
None
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. Affected versions
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.8.1
patch
Dependencies (1)
|
|
4.8.0
minor
2 CVEs
CVE-2019-14867
PYSEC-2026-636
GHSA-7hpj-hfcr-5qwm
PYSEC-2019-28
Jul 02, 2026
Code injection in FreeIPA
Critical
Network
Low
None
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. Affected versions
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.8.0
minor
Dependencies (1)
|
|
4.6.4
patch
2 CVEs
CVE-2019-14867
PYSEC-2026-636
GHSA-7hpj-hfcr-5qwm
PYSEC-2019-28
Jul 02, 2026
Code injection in FreeIPA
Critical
Network
Low
None
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. Affected versions
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.6.4
patch
Dependencies (1)
|
|
4.5.4
patch
|
4.5.4
patch
Dependencies (1)
|
|
4.6.5
patch
2 CVEs
CVE-2019-14867
PYSEC-2026-636
GHSA-7hpj-hfcr-5qwm
PYSEC-2019-28
Jul 02, 2026
Code injection in FreeIPA
Critical
Network
Low
None
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. Affected versions
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.6.5
patch
Dependencies (1)
|
|
4.8.0rc1
pre
|
4.8.0rc1
pre
Dependencies (1)
|
|
4.7.2
patch
2 CVEs
CVE-2019-14867
PYSEC-2026-636
GHSA-7hpj-hfcr-5qwm
PYSEC-2019-28
Jul 02, 2026
Code injection in FreeIPA
Critical
Network
Low
None
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. Affected versions
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.7.2
patch
Dependencies (1)
|
|
4.7.1
patch
2 CVEs
CVE-2019-14867
PYSEC-2026-636
GHSA-7hpj-hfcr-5qwm
PYSEC-2019-28
Jul 02, 2026
Code injection in FreeIPA
Critical
Network
Low
None
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. Affected versions
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.7.1
patch
Dependencies (1)
|
|
4.7.0
minor
2 CVEs
CVE-2019-14867
PYSEC-2026-636
GHSA-7hpj-hfcr-5qwm
PYSEC-2019-28
Jul 02, 2026
Code injection in FreeIPA
Critical
Network
Low
None
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. Affected versions
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.7.0
minor
Dependencies (1)
|
|
4.6.3
patch
2 CVEs
CVE-2019-14867
PYSEC-2026-636
GHSA-7hpj-hfcr-5qwm
PYSEC-2019-28
Jul 02, 2026
Code injection in FreeIPA
Critical
Network
Low
None
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. Affected versions
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.6.3
patch
Dependencies (1)
|
|
4.6.2
patch
2 CVEs
CVE-2019-14867
PYSEC-2026-636
GHSA-7hpj-hfcr-5qwm
PYSEC-2019-28
Jul 02, 2026
Code injection in FreeIPA
Critical
Network
Low
None
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. Affected versions
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.6.2
patch
Dependencies (1)
|
|
4.6.1
minor
1 CVE
CVE-2019-10195
GHSA-w4q7-f34x-vpgc
PYSEC-2019-168
PYSEC-2019-22
May 24, 2022
FreeIPA logs passwords embedded in commands in calls using batch
Medium
Network
Low
Low
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Affected versions
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
Fixed in
4.6.7
4.7.4
4.8.3
References
Updated Sep 20, 2024 · Source: OSV.dev |
4.6.1
minor
Dependencies (1)
|
|
4.5.2
patch
|
4.5.2
patch
Dependencies (1)
|
|
4.5.0
initial
|
4.5.0
initial
Dependencies (1)
|
|
4.4.0.dev1
pre
|
4.4.0.dev1
pre
|