CVE-2012-5484
EPSS 0.46%
Description
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
How to fix CVE-2012-5484
To remediate CVE-2012-5484, upgrade the affected package to a fixed version below.
- PyPI/freeipa—upgrade to 91f4af7e6af53e1c6bf17ed36cb2161863eddae4 or later
- PyPI/ipa—upgrade to 91f4af7e6af53e1c6bf17ed36cb2161863eddae4 or later
Is CVE-2012-5484 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 91f4af7e6af53e1c6bf17ed36cb2161863eddae4, < 18eea90ebb24a9c22248f0b7e18646cc6e3e3e0f, < a1991aeac19c3fec1fdd0d184c6760c90c9f9fc9, < 31e41eea6c2322689826e6065ceba82551c565aa, < a40285c5a0288669b72f9d991508d4405885bffc | from 0
- from 0, < 91f4af7e6af53e1c6bf17ed36cb2161863eddae4, < 18eea90ebb24a9c22248f0b7e18646cc6e3e3e0f, < a1991aeac19c3fec1fdd0d184c6760c90c9f9fc9, < 31e41eea6c2322689826e6065ceba82551c565aa, < a40285c5a0288669b72f9d991508d4405885bffc | from 0