CVE-2019-10195

MEDIUMCVSS 6.5/10EPSS 1.41%

Last modified

CVE-2019-10195 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. EPSS estimates a 1.41% chance of exploitation in the next 30 days.

Description

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
1.41%

69.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
FreeipaFreeipa>= 4.6.0, < 4.6.7
FreeipaFreeipa>= 4.7.0, < 4.7.4
FreeipaFreeipa>= 4.8.0, < 4.8.3
FedoraprojectFedora30
FedoraprojectFedora31

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-10195?
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.
How severe is CVE-2019-10195?
CVE-2019-10195 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 1.41% probability of exploitation in the next 30 days.
How do I fix CVE-2019-10195?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-10195?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST