CyberRota Analysis
AI-GeneratedA vulnerability exists in FreeIPA's idp-add command, where inadequate validation of the --organization and --base-url inputs allows authenticated users to bypass LDAP access controls. This flaw enables any IPA principal to enumerate server environment variables and potentially induce a denial of service through memory exhaustion. Organizations using FreeIPA should prioritize patching this issue to safeguard against unauthorized data exposure and service disruption.
Original NVD Description
A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.