---
title: "CVE-2017-12169\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2017-12169?format=md
keywords: index, follow
---

# CVE-2017-12169

Publication date 10 January 2018

Last updated 11 July 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2017-12169?format=md#impact-score)

Toggle side navigation

## Description

It was found that FreeIPA 4.2.0 and later could disclose password hashes to
users having the 'System: Read Stage Users' permission. A remote,
authenticated attacker could potentially use this flaw to disclose the
password hashes belonging to Stage Users. This security issue does not
result in disclosure of password hashes belonging to active standard users.
NOTE: some developers feel that this report is a suggestion for a design
change to Stage User activation, not a statement of a vulnerability.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2017-12169?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| freeipa | 26.04 LTS resolute | Vulnerable |
| 25.10 questing | Ignored end of life, was needed |
| 25.04 plucky | Ignored end of life, was needed |
| 24.10 oracular | Ignored end of life, was needed |
| 24.04 LTS noble | Vulnerable |
| 23.10 mantic | Ignored end of life, was needed |
| 23.04 lunar | Ignored end of life, was needed |
| 22.10 kinetic | Ignored end of life, was needed |
| 22.04 LTS jammy | Vulnerable |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Vulnerable |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.10 cosmic | Ignored end of life |
| 18.04 LTS bionic | Vulnerable |
| 17.10 artful | Ignored end of life |
| 17.04 zesty | Ignored end of life |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Vulnerable |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [ebarretto](https://launchpad.net/~ebarretto)

No fix available as of 2019-02-14

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12169)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-12169)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-12169)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2017-12169)

### Other references

* <https://bugzilla.redhat.com/show_bug.cgi?id=1487697>
* <https://www.cve.org/CVERecord?id=CVE-2017-12169>
