The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, which allows remote attackers to obtain the Kerberos master key via an anonymous LDAP query.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2008-09-12T16:00:00
Updated: 2008-09-24T09:00:00
Reserved: 2008-07-24T00:00:00
Link: CVE-2008-3274
JSON object: View
NVD Information
Status : Modified
Published: 2008-09-12T16:56:20.477
Modified: 2023-02-13T02:19:20.203
Link: CVE-2008-3274
JSON object: View
Redhat Information
No data.
CWE