CVE-2012-5484: Red Hat Freeipa

High severity, CVSS 7.9. EPSS: 0.6% chance of exploitation in the next 30 days.

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

Affected products

  • Red Hat Freeipa: version 2.0.0 only; version 2.0.1 only; version 2.1.0 only; version 2.1.1 only; version 2.1.3 only; version 2.1.4 only; …

Published 2013-01-27. Last modified 2026-06-16.