6.8
CVSSv2

CVE-2011-3636

Published: 08/12/2011 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA prior to 2.1.4 allows remote malicious users to hijack the authentication of administrators for requests that make configuration changes.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat freeipa 1.2.2

redhat freeipa 1.1.0

redhat freeipa 2.1.0

redhat freeipa 2.0.0

redhat freeipa 2.1.1

redhat freeipa 1.2.1

redhat freeipa 1.0.0

redhat freeipa 1.9.0

redhat freeipa 0.99

redhat freeipa 2.0.1

redhat freeipa 0.99698641-20080218

redhat freeipa 0.99698-20080228

redhat freeipa 1.1.1

redhat freeipa

redhat freeipa 2.1.2

redhat freeipa 1.2.0

Vendor Advisories

Synopsis Moderate: ipa security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated ipa packages that fix one security issue and several bugs are nowavailable for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact A C ...