Candidate: CVE-2019-10195 PublicDate: 2019-11-27 08:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10195 https://pagure.io/freeipa/c/02ce407f5e10e670d4788778037892b58f80adc0 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10195 https://www.freeipa.org/page/Releases/4.6.7 https://www.freeipa.org/page/Releases/4.7.4 https://www.freeipa.org/page/Releases/4.8.3 Description: A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N [6.5 MEDIUM] Patches_freeipa: upstream: https://pagure.io/freeipa/c/02ce407f5e10e670d4788778037892b58f80adc0 upstream_freeipa: released (4.8.3-1) precise/esm_freeipa: DNE trusty_freeipa: ignored (out of standard support) trusty/esm_freeipa: needed xenial_freeipa: ignored (end of standard support, was needed) bionic_freeipa: needed disco_freeipa: ignored (reached end-of-life) eoan_freeipa: ignored (reached end-of-life) focal_freeipa: needed groovy_freeipa: ignored (reached end-of-life) hirsute_freeipa: ignored (reached end-of-life) impish_freeipa: needed jammy_freeipa: needed devel_freeipa: needed