2.1
CVSSv2

CVE-2019-14826

Published: 17/09/2019 Updated: 09/10/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 3.6 | Exploitability Score: 0.8
VMScore: 188
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freeipa freeipa

redhat enterprise linux 7.0

redhat enterprise linux 8.0

Vendor Advisories

Debian Bug report logs - #940913 freeipa: CVE-2019-14826 Package: src:freeipa; Maintainer for src:freeipa is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 21 Sep 2019 19:15:02 UTC Severity: important Tags: security, upstream Found in ...
Impact: Low Public Date: 2019-09-17 CWE: CWE-613 Bugzilla: 1746944: CVE-2019-14826 ipa: Session not ter ...

Github Repositories

-python-tda-bug-hunt-0 DEPENDENCY #six==1160 VULNERABLE DEPENDENCY IN THE PACKAGE TREE #freeipa==462 VULNERABILITIES CVE-2019-14826 DEPENDENCY #freeipa==454 VULNERABLE DEPENDENCY IN THE PACKAGE TREE #jinja2==312 VULNERABILITIES CVE-2019-10195

-python-tda-bug-hunt-0 DEPENDENCY #six==1160 VULNERABLE DEPENDENCY IN THE PACKAGE TREE #freeipa==462 VULNERABILITIES CVE-2019-14826 DEPENDENCY #freeipa==454 VULNERABLE DEPENDENCY IN THE PACKAGE TREE #jinja2==312 VULNERABILITIES CVE-2019-10195