Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Untriaged
(browse all)
created 4 months, 3 weeks ago
Freeipa: delegation rules allow a proxy service to impersonate any user to access another target service

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed_to_delegate() function: If the target service argument is NULL, then it means the KDC is probing for general constrained delegation rules and not checking a specific S4U2Proxy request. In FreeIPA 4.11.0, the behavior of ipadb_match_acl() was modified to match the changes from upstream MIT Kerberos 1.20. However, a mistake resulting in this mechanism applies in cases where the target service argument is set AND where it is unset. This results in S4U2Proxy requests being accepted regardless of whether or not there is a matching service delegation rule.

Affected products

ipa
  • *
freeipa
  • <4.12.1
  • <4.11.2
idm:DL1
  • *
idm:client/ipa

Matching in nixpkgs

pkgs.ipam

Cli based IPAM written in Go with PowerDNS support

pkgs.tipa

Phonetic font for TeX

  • nixos-unstable -

pkgs.nipap

Neat IP Address Planner

  • nixos-unstable -

pkgs.freeipa

Identity, Policy and Audit system

  • nixos-unstable -

pkgs.ipafont

Japanese font package with Mincho and Gothic fonts

  • nixos-unstable -

pkgs.ipatool

Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store

  • nixos-unstable -

pkgs.codipack

Fast gradient evaluation in C++ based on Expression Templates

  • nixos-unstable -

pkgs.gruut-ipa

Library for manipulating pronunciations using the International Phonetic Alphabet (IPA)

  • nixos-unstable -

pkgs.iniparser

Free standalone ini file parsing library

  • nixos-unstable -

pkgs.ipaexfont

Japanese font package with Mincho and Gothic fonts

  • nixos-unstable -

pkgs.multipass

Ubuntu VMs on demand for any workstation

  • nixos-unstable -

pkgs.nipap-cli

Neat IP Address Planner CLI

  • nixos-unstable -

pkgs.nipap-www

Neat IP Address Planner CLI, web UI

  • nixos-unstable -

pkgs.uriparser

Strictly RFC 3986 compliant URI parsing library

  • nixos-unstable -

pkgs.frangipanni

Convert lines of text into a tree structure

  • nixos-unstable -

Package maintainers