OSV 1.4.0 · unreviewed · 修改于 2026-08-20 20:31
发布时间
2026-08-20 20:31
GitHub 审查时间
—
NVD 发布时间
2026-08-20 19:16
源文件
advisories/unreviewed/2026/08/GHSA-q4ph-46qc-4w6x/GHSA-q4ph-46qc-4w6x.json
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.
该公告没有提供结构化的受影响软件包信息。