FreeIPA contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is due to the program failing to restrict access when handling outgoing and incoming keys of a Cross-Realm Kerberos trust with an Active Directory (AD) when using IPA LDAP ACIs. With a specially crafted Kereberos ticket, a remote attacker can gain access to multiple attribute keys and impersonate other users