SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10195

An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

MEDIUM 6.5EPSS 1.81%

Does this matter?

Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.81% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-532
Affected
freeipa/freeipa · fedoraproject/fedora
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.