Candidate: CVE-2014-7828 PublicDate: 2014-11-19 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7828 https://fedorahosted.org/freeipa/ticket/4690 Description: FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind. Ubuntu-Description: Notes: ebarretto> This is a FreeIPA 4.0.x issue, so marking Trusty as not affected ebarretto> Although Trusty also has the code, it differs from 4.0.x version Bugs: Priority: high Discovered-by: Assigned-to: CVSS: Patches_freeipa: upstream: https://www.redhat.com/archives/freeipa-devel/2014-November/msg00068.html upstream_freeipa: needs-triage lucid_freeipa: DNE precise_freeipa: ignored (reached end-of-life) precise/esm_freeipa: DNE (precise was needed) trusty_freeipa: not-affected trusty/esm_freeipa: not-affected utopic_freeipa: ignored (reached end-of-life) vivid_freeipa: not-affected (4.0.5-1) vivid/stable-phone-overlay_freeipa: DNE vivid/ubuntu-core_freeipa: DNE wily_freeipa: not-affected (4.0.5-1) xenial_freeipa: not-affected (4.0.5-1) yakkety_freeipa: not-affected (4.0.5-1) zesty_freeipa: not-affected (4.0.5-1) artful_freeipa: not-affected (4.0.5-1) bionic_freeipa: not-affected (4.0.5-1) cosmic_freeipa: not-affected (4.0.5-1) devel_freeipa: not-affected (4.0.5-1)