4
CVSSv2

CVE-2019-10195

Published: 27/11/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 357
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A flaw was found in IPA, all 4.6.x versions prior to 4.6.7, all 4.7.x versions prior to 4.7.4 and all 4.8.x versions prior to 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freeipa freeipa

fedoraproject fedora 30

fedoraproject fedora 31

Vendor Advisories

Synopsis Important: ipa security and bug fix update Type/Severity Security Advisory: Important Topic An update for ipa is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base sc ...
Synopsis Important: idm:DL1 security update Type/Severity Security Advisory: Important Topic An update for the idm:DL1 module is now available for Red Hat Enterprise Linux 80 Update Services for SAP SolutionsRed Hat Product Security has rated this update as having a security impact of Important A Common ...
A flaw was found in IPA, all 46x versions before 467, all 47x versions before 474 and all 48x versions before 483, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA ...

Github Repositories

-python-tda-bug-hunt-0 DEPENDENCY #six==1160 VULNERABLE DEPENDENCY IN THE PACKAGE TREE #freeipa==462 VULNERABILITIES CVE-2019-14826 DEPENDENCY #freeipa==454 VULNERABLE DEPENDENCY IN THE PACKAGE TREE #jinja2==312 VULNERABILITIES CVE-2019-10195

-python-tda-bug-hunt-0 DEPENDENCY #six==1160 VULNERABLE DEPENDENCY IN THE PACKAGE TREE #freeipa==462 VULNERABILITIES CVE-2019-14826 DEPENDENCY #freeipa==454 VULNERABLE DEPENDENCY IN THE PACKAGE TREE #jinja2==312 VULNERABILITIES CVE-2019-10195