← Back

CVE-2019-10195

nvd nist
Published: Nov 27, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

Affected (5)

1 product
Freeipa
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Freeipa
From 4.6.0 to 4.6.7
From 4.7.0 to 4.7.4
From 4.8.0 to 4.8.3
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31

References (16)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Release Notes
Source: secalert@redhat.com
Release Notes
Source: secalert@redhat.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes

Timeline

No history available yet.