CVE-2023-5455
NixOS vulnerability analysis and mitigation

Overview

A Cross-site request forgery (CSRF) vulnerability was discovered in ipa/session/login_password endpoint in all supported versions of IPA (CVE-2023-5455). The vulnerability was identified during community penetration testing and disclosed on January 10, 2024 (FreeIPA Release Notes).

Technical details

The vulnerability exists because certain HTTP endpoints in FreeIPA do not ensure proper CSRF protection. The system uses HTTP Referer header for CSRF protection but it is not applied universally, specifically the URI ipa/session/login_password is not protected. The vulnerability has a CVSS v3.1 base score of 6.5 (MODERATE) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N (NVD).

Impact

An attacker could exploit this vulnerability to trick users into submitting requests that perform actions on their behalf, potentially leading to a loss of confidentiality and system integrity. However, due to implementation details, the flaw cannot be used for reflection of a cookie representing an already logged-in user - an attacker would always have to go through a new authentication attempt (FreeIPA Release Notes).

Mitigation and workarounds

The vulnerability has been patched in multiple FreeIPA versions: 4.6.10, 4.9.14, 4.10.3, and 4.11.1. The fix involves implementing proper CSRF protection by checking the HTTP Referer header on all requests (FreeIPA Release Notes). Red Hat has released security updates for affected versions across RHEL 7, 8, and 9 platforms (Red Hat CVE).

Community reactions

The FreeIPA team acknowledged and thanked Egor Uvarov for discovering and reporting this security issue. Red Hat Product Security assessed the overall severity of this issue as MODERATE (FreeIPA Release Notes).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management