Impact
A low‑privilege authenticated user can submit an oversized One‑Time Password key value to FreeIPA’s otptoken‑add function. The system decodes and re‑encodes this key without bounding its size, resulting in excessive CPU and memory consumption that can degrade the availability of the IPA service.
Affected Systems
Red Hat Enterprise Linux 6, 7, 8, 9 and 10 – which include the vulnerable FreeIPA component. All listed distributions are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, while no EPSS score is available, showing limited data on exploit likelihood. It is not listed in the CISA KEV catalog. The vulnerability requires the attacker to have authenticated access; the attack vector is therefore an authenticated local user sending a large HTTP request to the "/ipa/session/json" endpoint, which triggers the resource exhaustion path.
OpenCVE Enrichment