CVE-2015-5284: Freeipa

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.

Affected products

  • Freeipa Freeipa: up to and including 4.2.1

Published 2017-09-21. Last modified 2026-06-17.