Clear Text Password Exposure in FreeIPA's Batch Processing API
CVE-2019-10195
5.7MEDIUM
Summary
A vulnerability exists in FreeIPA where the batch processing API can inadvertently log user passwords in clear text on the FreeIPA masters. While batch processing with passwords is not enabled by default, it can be activated through third-party components. If an attacker gains access to system logs, they can exploit this flaw, leading to unauthorized exposure of sensitive information.
Affected Version(s)
IPA all IPA 4.6.x versions before 4.6.7
IPA all IPA 4.7.x versions before 4.7.4
IPA all IPa 4.8.x versions before 4.8.3
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved