---
title: "CVE-2024-3183\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2024-3183?format=md
keywords: index, follow
---

# CVE-2024-3183

Publication date 12 June 2024

Last updated 4 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.1 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2024-3183?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is
encrypted using the client’s session key. This key is different for each
new session, which protects it from brute force attacks. However, the
ticket it contains is encrypted using the target principal key directly.
For user principals, this key is a hash of a public per-principal
randomly-generated salt and the user’s password.
If a principal is compromised it means the attacker would be able to
retrieve tickets encrypted to any principal, all of them being encrypted by
their own key directly. By taking these tickets and salts offline, the
attacker could run brute force attacks to find character strings able to
decrypt tickets when combined to a principal salt (i.e. find the
principal’s password).

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| freeipa | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 23.10 mantic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.1 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.1 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3183)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2024-3183)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2024-3183)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2024-3183)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2024-3183>
* <https://bugzilla.redhat.com/show_bug.cgi?id=2270685>
