CVE-2024-1481: Red Hat Enterprise Linux 7

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

Affected products

  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 8100020240307184541.6d180cd9 (fixed in 8100020240307184541.6d180cd9); before 8100020240307185118.fc00487d (fixed in 8100020240307185118.fc00487d)
  • Red Hat Red Hat Enterprise Linux 9: before 0:4.11.0-9.el9_4 (fixed in 0:4.11.0-9.el9_4)

Published 2024-04-10. Last modified 2026-06-17.