logo

Attacking FreeIPA — Part IV: CVE-2020–10747

ID: 6ccd4c66-9c4f-5d70-b5b3-33cdcfef9a99

STIX ID: report--6ccd4c66-9c4f-5d70-b5b3-33cdcfef9a99

Feed Name: SpecterOps Blog

Threat Score
55/100

Date Published: 2020-06-28

Date Updated: 2026-04-30

Author: Julian Catrambone

...
...

This report details an offensive assessment of FreeIPA where a misintegration allowed privilege escalation to UID 0: an attacker with 'User Administrators' privileges can create a domain user named 'root', obtain a ticket, and SSH into the local root account—also bypassing HBAC rules. The issue was reported and a patch exists, but Red Hat ultimately revoked CVE-2020-10747 and classified the behavior as expected rather than a security boundary failure; administrators are advised to treat privileged roles as highly sensitive and monitor them closely.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.