vulnerability

CentOS Linux: CVE-2020-1722: Moderate: ipa security, bug fix, and enhancement update (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:H/Au:N/C:N/I:N/A:C)
Published
Apr 27, 2020
Added
Oct 1, 2020
Modified
May 25, 2023

Description

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.

Solutions

centos-upgrade-bind-dyndb-ldapcentos-upgrade-bind-dyndb-ldap-debuginfocentos-upgrade-bind-dyndb-ldap-debugsourcecentos-upgrade-custodiacentos-upgrade-ipa-clientcentos-upgrade-ipa-client-commoncentos-upgrade-ipa-client-debuginfocentos-upgrade-ipa-client-epncentos-upgrade-ipa-client-sambacentos-upgrade-ipa-commoncentos-upgrade-ipa-debuginfocentos-upgrade-ipa-debugsourcecentos-upgrade-ipa-healthcheckcentos-upgrade-ipa-healthcheck-corecentos-upgrade-ipa-python-compatcentos-upgrade-ipa-selinuxcentos-upgrade-ipa-servercentos-upgrade-ipa-server-commoncentos-upgrade-ipa-server-debuginfocentos-upgrade-ipa-server-dnscentos-upgrade-ipa-server-trust-adcentos-upgrade-ipa-server-trust-ad-debuginfocentos-upgrade-opendnsseccentos-upgrade-opendnssec-debuginfocentos-upgrade-opendnssec-debugsourcecentos-upgrade-python2-ipaclientcentos-upgrade-python2-ipalibcentos-upgrade-python2-ipaservercentos-upgrade-python3-custodiacentos-upgrade-python3-ipaclientcentos-upgrade-python3-ipalibcentos-upgrade-python3-ipaservercentos-upgrade-python3-jwcryptocentos-upgrade-python3-kdcproxycentos-upgrade-python3-pyusbcentos-upgrade-python3-qrcodecentos-upgrade-python3-qrcode-corecentos-upgrade-python3-yubicocentos-upgrade-slapi-niscentos-upgrade-slapi-nis-debuginfocentos-upgrade-slapi-nis-debugsourcecentos-upgrade-softhsmcentos-upgrade-softhsm-debuginfocentos-upgrade-softhsm-debugsourcecentos-upgrade-softhsm-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.