SCA: security update for freeipa, ipa (GHSA-7hpj-hfcr-5qwm)

high Tenable Self-Hosted Container Security Plugin ID 412093

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x
versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA
server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb
principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be
executed on the server hosting the IPA server. (CVE-2019-14867)

See Also

https://github.com/advisories/GHSA-7hpj-hfcr-5qwm

Plugin Details

Severity: High

ID: 412093

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-14867

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/6/2021

Vulnerability Publication Date: 11/26/2019

Reference Information

CVE: CVE-2019-14867