CVE-2012-5484

high
Published 2013-01-27 · Modified 2026-02-22
CVSS v3
CVSS v2
7.9
VIR risk
7.9

Description

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.freeipa.org/page/CVE-2012-5484

Package impact

EcosystemPackageVulnerableFixed
python PyPIfreeipa<a40285c5a0288669b72f9d991508d4405885bffc91f4af7e6af53e1c6bf17ed36cb2161863eddae4
python PyPIipa<a40285c5a0288669b72f9d991508d4405885bffc91f4af7e6af53e1c6bf17ed36cb2161863eddae4

Application impact

VendorProductVersionsFixed
redhatfreeipa2.0.0
redhatfreeipa2.0.1
redhatfreeipa2.1.0
redhatfreeipa2.1.1
redhatfreeipa2.1.3
redhatfreeipa2.1.4
redhatfreeipa2.2.1
redhatfreeipa3.0.0
redhatfreeipa3.0.1
redhatfreeipa3.0.2
redhatfreeipa3.1.1

References

CWEs

CWE-310

Verify integrity in audit chain (admin only). AS-IS.