CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-11029: Freeipa: administrative user data leaked through systemd journal

Description

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials.

Classification

CVE ID: CVE-2024-11029

Affected Products

Vendor: Red Hat

Product: Red Hat Enterprise Linux 9

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.81% (scored less or equal to compared to others)

EPSS Date: 2025-02-13 (when was this score calculated)

References

https://access.redhat.com/errata/RHSA-2025:0334
https://access.redhat.com/security/cve/CVE-2024-11029
https://bugzilla.redhat.com/show_bug.cgi?id=2325557

Timeline