Impact
The flaw lives in the FreeIPA idp‑add command. Insufficient validation of the --organization/--base‑url arguments allows the attacker to reach a constrained eval() call before the LDAP access control check runs. The eval call executes shell code derived from user‑supplied data, enabling any authenticated IPA principal—regardless of privilege—to read environment variables of the server process and to trigger a memory‑exhaustion denial of service.
Affected Systems
Red Hat Enterprise Linux 6 through 10 running FreeIPA are affected. The vulnerability is present in the FreeIPA packages shipped with these RHEL releases. The known CPE identifiers include versions 6, 7, 8, 9, and 10 of Red Hat Enterprise Linux.
Risk and Exploitability
The detected CVSS base score is 8.1, indicating high severity. No EPSS score is available. The vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires an authenticated IPA user; it is likely carried out over the network by executing idp‑add with crafted parameters. Successful exploitation exposes the process’s environment and can crash the service by exhausting available memory.
OpenCVE Enrichment