← Back to CVE List

CVE-2017-11191

Published: 2017-09-28T01:29Z
Last Modified: 2024-11-21T03:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern > MITRE Terms of Use apply – see LICENSE‑MITRE.txt