CVE-2023-5455: Fedoraproject Fedora

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

Affected products

  • Fedoraproject Fedora: version 38 only; version 39 only; version 40 only
  • Freeipa Freeipa: before 4.6.10 (fixed in 4.6.10); from 4.7.0, before 4.9.14 (fixed in 4.9.14); from 4.10.0, before 4.10.3 (fixed in 4.10.3); version 4.11.0 only
  • Red Hat Codeready Linux Builder: affected versions not specified
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only; version 8.4 only; version 9.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Eus: version 8.6 only; version 8.8 only; version 9.0 only; version 9.2 only
  • Red Hat Enterprise Linux For Arm 64 Eus: version 8.8 only; version 9.0 only; version 9.2 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 7.0 only; version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 8.6 only; version 8.8 only; version 9.0 only; version 9.2 only
  • Red Hat Enterprise Linux For Power Big Endian: version 7.0 only
  • Red Hat Enterprise Linux For Power Little Endian: version 7.0 only; version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 8.6 only; version 8.8 only; version 9.0 only; version 9.2 only
  • Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
  • Red Hat Enterprise Linux Server: version 9.0 only; version 9.2 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only; version 9.2 only
  • Red Hat Enterprise Linux Server For IBM Z Systems: version 9.2 only
  • Red Hat Enterprise Linux Server For Power Little Endian Update Services For SAP Solutions: version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Update Services For SAP Solutions: version 8.2 only; version 8.6 only; version 9.0 only; version 9.2 only
  • Red Hat Enterprise Linux Update Services For SAP Solutions: version 9.0 only; version 9.2 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2024-01-10. Last modified 2026-06-17.