{"id":"GHSA-7hpj-hfcr-5qwm","summary":"Code injection in FreeIPA","details":"A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.","aliases":["CVE-2019-14867","PYSEC-2019-28","PYSEC-2026-636"],"modified":"2026-07-06T08:11:46.413084191Z","published":"2021-12-06T18:17:38Z","database_specific":{"cwe_ids":["CWE-400","CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-12-06T18:13:11Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14867"},{"type":"WEB","url":"https://access.redhat.com/errata/RHBA-2019:4268"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2020:0378"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14867"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7hpj-hfcr-5qwm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/ipa/PYSEC-2019-28.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-db/tree/main/vulns/ipa/PYSEC-2019-28.yaml"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/67SEUWJAJ5RMH5K4Q6TS2I7HIMXUGNKF"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLFL5XDCJ3WT6JCLCQVKHZBLHGW7PW4T"},{"type":"WEB","url":"https://www.freeipa.org/page/Releases/4.6.7"},{"type":"WEB","url":"https://www.freeipa.org/page/Releases/4.7.4"},{"type":"WEB","url":"https://www.freeipa.org/page/Releases/4.8.3"}],"affected":[{"package":{"name":"ipa","ecosystem":"PyPI","purl":"pkg:pypi/ipa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.6.2"},{"fixed":"4.6.7"}]}],"versions":["4.6.2","4.6.3","4.6.4","4.6.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-7hpj-hfcr-5qwm/GHSA-7hpj-hfcr-5qwm.json"}},{"package":{"name":"ipa","ecosystem":"PyPI","purl":"pkg:pypi/ipa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.7.0"},{"fixed":"4.7.4"}]}],"versions":["4.7.0","4.7.1","4.7.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-7hpj-hfcr-5qwm/GHSA-7hpj-hfcr-5qwm.json"}},{"package":{"name":"ipa","ecosystem":"PyPI","purl":"pkg:pypi/ipa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.8.0"},{"fixed":"4.8.3"}]}],"versions":["4.8.0","4.8.1","4.8.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-7hpj-hfcr-5qwm/GHSA-7hpj-hfcr-5qwm.json"}},{"package":{"name":"freeipa","ecosystem":"PyPI","purl":"pkg:pypi/freeipa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.6.2"},{"fixed":"4.6.7"}]}],"versions":["4.6.2","4.6.3","4.6.4","4.6.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-7hpj-hfcr-5qwm/GHSA-7hpj-hfcr-5qwm.json"}},{"package":{"name":"freeipa","ecosystem":"PyPI","purl":"pkg:pypi/freeipa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.7.0"},{"fixed":"4.7.4"}]}],"versions":["4.7.0","4.7.1","4.7.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-7hpj-hfcr-5qwm/GHSA-7hpj-hfcr-5qwm.json"}},{"package":{"name":"freeipa","ecosystem":"PyPI","purl":"pkg:pypi/freeipa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.8.0"},{"fixed":"4.8.3"}]}],"versions":["4.8.0","4.8.1","4.8.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-7hpj-hfcr-5qwm/GHSA-7hpj-hfcr-5qwm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}