The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/81486
https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-0019
http://www.securityfocus.com/bid/57542
http://www.freeipa.org/page/Releases/3.1.2