#8326 CVE-2020-10747
Closed: fixed by abbra. Opened by cheimes.

Issue

[description of the issue]

Steps to Reproduce

1.
2.
3.

Actual behavior

(what happens)

Expected behavior

(what do you expect to happen)

Version/Release/Distribution

$ rpm -q freeipa-server freeipa-client ipa-server ipa-client 389-ds-base pki-ca krb5-server

Additional info:

https://bugzilla.redhat.com/show_bug.cgi?id=1810160
https://bugzilla.redhat.com/show_bug.cgi?id=1835433 (RHEL 7)
https://bugzilla.redhat.com/show_bug.cgi?id=1835434 (RHEL 8)


Metadata Update from @cheimes:
- Custom field on_review adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1810160

ipa-4-6:

  • 62400d6d240c1bb68987a1ff194ee7cd6c6d3cf0 Prevent local account takeover

ipa-4-8:

  • 930f4b3d1dc03f9e365b007b027d65e146a08f05 Prevent local account takeover

master:

  • 4911a3f05514a7c0ac66e4ef5004581cced8519f Prevent local account takeover

Metadata Update from @abbra:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata Update from @abbra:
- Issue private status set to: False (was: True)

Metadata