FreeIPA contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is due to CA certificates being handled improperly when joining an IPA domain. This may allow a remote attacker to gain access to CA certificates and spoof an IPA server via a Man-in-the-Middle attack.