CVE-2017-11191 — FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had — CVE Database · The Intelligence Room