https://www.facebook.com/itzonepakistan
×

Archives

  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2021
  • February 2021
  • December 2020
  • November 2020
  • April 2019

Categories

  • Business
  • DMS
  • Networking
  • Technology
  • Tips
  • Uncategorized

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

HOW TO SHOP

1 Login or create new account.
2 Review your order.
3 Payment & FREE shipment

If you still have problems, please let us know, by sending an email to support@website.com . Thank you!

SHOWROOM HOURS

Mon-Fri 9:00AM - 6:00AM
Sat - 9:00AM-5:00PM
Sundays by appointment only!
social sharing

SIGN IN YOUR ACCOUNT TO HAVE ACCESS TO DIFFERENT FEATURES

FORGOT YOUR PASSWORD?

FORGOT YOUR DETAILS?

AAH, WAIT, I REMEMBER NOW!
QUESTIONS? CALL: 03144 166 777
  • LOGIN
  • SUPPORT

IT Zone Pakistan

IT Zone Pakistan

IT Zone Pakistan | Graphics, Web Design, ERP, Document Scanning Services, 3d interior design

T (31) 44 166 777
Email: sales@itzonepakistan.com

IT Zone Pakistan
II Chundriger Road Uni Plaza Karachi-Pakistan

Open in Google Maps
  • Home – IT Zone
  • About Us
  • Our Services
    • Office Paper Shredding Service – Free of Charge!
    • Document Scanning Services
    • Document Management Software
    • Office Computer Scrap Buying
  • Shop
  • BLOG & STORIES
    • EVENTS
  • Contact Us
  • MY CART
    No products in cart.
FREEQUOTE
  • Home
  • BLOG & STORIES
  • Uncategorized
  • Vulnerability in open source identity management system Free IPA could lead to XXE attacks – The Daily Swig
June 4, 2025

Vulnerability in open source identity management system Free IPA could lead to XXE attacks – The Daily Swig

Vulnerability in open source identity management system Free IPA could lead to XXE attacks – The Daily Swig

by admin / Thursday, 27 October 2022 / Published in Uncategorized

Cyber Warfare
Russia is ‘failing’ in its mission to destabilize Ukraine’s networks
Hacker-powered security
Human error bugs increasingly making a splash, study indicates
In focus
Software supply chain attacks – everything you need to know
Special report
Inaugural report outlines strengths and weaknesses exposed by momentous security flaw
Chromium site isolation bypass
Flaw that opened the door to cookie modification and data theft resolved
Bug Bounty Radar
The latest programs for September 2022
Cybersecurity conferences
A schedule of events in 2022 and beyond
Attackers could ‘take full control of the infrastructure’, warn researchers
UPDATED A vulnerability in Free IPA could lead to XML external entity (XXE) attacks, researchers have warned.
FreeIPA is a free and open source identity management system and is the upstream project of Red Hat Identity Management.
A flaw, tracked as CVE-2022-2414, was found in the pki-core package, a security advisory from Red Hat warns.
Read more of the latest news about security vulnerabilities
“Access to external entities when parsing XML documents can lead to XML external entity attacks.
“This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.”
XXE allows injecting arbitrary entities into an XML document and performing malicious actions such as local file reading or sending HTTP requests into an internal network.

The latter could lead to remote code execution (RCE) if there are unpatched applications inside an internal network.

The vulnerability, which has a severity rating of 7.5 (high), was discovered by researcher Egor Dimintrenko of security research team PT Swarm.

The security flaw takes place in the certification system, called DogTag, Dimitrenko told The Daily Swig.

“DogTag can be used as a PKI service for any project, but it’s well known as a part of FreeIPA system. Since DogTag is integrated into FreeIPA, FreeIPA is vulnerable if still unpatched,” he said.

“It’s also worth mentioning that main impact of the vulnerability is a risk of configuration file reading, which contains password for Directory Manager user,” Dimitrenko said.

“Directory Manager is a main entity in the application and control Directory Server. By compromising this user, an attacker is able to connect to directory server and read any high sensitive data like user credentials and then make a lateral movement in infrastructure.

“Particularly in FreeIPA this configuration file doesn’t contain a Directory Manager password by default, but in some cases it takes place, for example when an administrator change Directory Manager password.”

The vulnerability affects Red Hat Enterprise Linux 6-9 and Red Hat Certificate System 9 and 10.

Dimitrenko said that exploitation of the bug is “extremely simple” due to the fact that it doesn’t require any credentials and an attacker just has to find an accessible endpoint.

The vulnerability has been patched by Red Hat in all versions apart from Linux 6, which is out of scope. There are no known mitigations available and Red Hat urges users to update.

Dimitrenko commented: “It’s nice to see that there are many companies which support responsible disclosure and communicate with researchers, instead of ignoring them and hiding their problems.”
This article has been updated to include further comment.

YOU MAY ALSO LIKE Secure Open Source Rewards program launched to help protect critical upstream software
Jessica Haworth
@JesscaHaworth
Burp Suite
Vulnerabilities
Customers
Company
Insights
© 2022 PortSwigger Ltd.

source

  • Tweet

About admin

What you can read next

Epson WorkForce ES-865 Color Duplex Document Scanner Review – PCMag
Best all-in-one printers of 2025 – TechRadar
The Best Scanners for 2025 – Yahoo! Voices

Recent Posts

  • Need to Sign or Scan Papers? Here's How To Use Your iPhone's Hidden Document Scanner – MSN

    source...
  • The Best Scanners We've Tested (June 2025) – PCMag

    source...
  • Keypoint Intelligence Releases New Insights on the Future of the Document Scanner Market – Taiwan News

    source...
  • Civica acquires Gateway Computing – Local Government Chronicle

    source...
  • Google Drive's Document Scanner is Getting an Auto Enhancement Feature – Gadgets 360

    source...

Recent Comments

    Featured Posts

    • Need to Sign or Scan Papers? Here's How To Use Your iPhone's Hidden Document Scanner – MSN

      0 comments
    • The Best Scanners We've Tested (June 2025) – PCMag

      0 comments
    • Keypoint Intelligence Releases New Insights on the Future of the Document Scanner Market – Taiwan News

      0 comments
    • Civica acquires Gateway Computing – Local Government Chronicle

      0 comments
    • Google Drive's Document Scanner is Getting an Auto Enhancement Feature – Gadgets 360

      0 comments

    Archives

    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2021
    • February 2021
    • December 2020
    • November 2020
    • April 2019

    Categories

    • Business
    • DMS
    • Networking
    • Technology
    • Tips
    • Uncategorized

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    GET A FREE QUOTE

    Please fill this for and we'll get back to you as soon as possible!

    FACEBOOK

    2,175
    LIKES

    TWITTER

    1,050
    Followers

    PINTEREST

    101
    follower

    FOOTER MENU

    • Terms and Conditions
    • F.A.Q.
    • Our Services
    • BLOG & STORIES

    NEWSLETTER SIGNUP

    By subscribing to our mailing list you will always be update with the latest news from us.

    We never spam!

    GET IN TOUCH

    II Chundriger Road Uni Plaza Karachi-Pakistan
    Email: Info@Itzonepakistan.com
    Phone:
    Direct+92-314-4166-777
    Sales+92-313-8854-133

    Social Platform

    • Tweet
    • Pin It

    RSS ARY NEWS

    • Musk calls Trump’s tax-cut and spending bill ‘a disgusting abomination’ June 4, 2025
    • GET SOCIAL
    IT Zone Pakistan

    Copyright @2024-25. All rights reserved | Design & Develop IT Zone Pakistan.

    TOP