VYPR
Medium severity6.5NVD Advisory· Published Nov 27, 2019· Updated Jun 17, 2026

CVE-2019-10195

CVE-2019-10195

Description

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
freeipaPyPI
>= 4.6.0, < 4.6.74.6.7
freeipaPyPI
>= 4.7.0, < 4.7.44.7.4
freeipaPyPI
>= 4.8.0, < 4.8.34.8.3
ipaPyPI
>= 4.6.0, < 4.6.74.6.7
ipaPyPI
>= 4.7.0, < 4.7.44.7.4
ipaPyPI
>= 4.8.0, < 4.8.34.8.3

Affected products

6
  • cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:*
    Range: >=4.6.0,<4.6.7
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
  • ghsa-coords2 versions
    >= 4.6.0, < 4.6.7+ 1 more
    • (no CPE)range: >= 4.6.0, < 4.6.7
    • (no CPE)range: >= 4.6.0, < 4.6.7
  • Red Hat/IPAv5
    Range: all IPA 4.6.x versions before 4.6.7

Patches

Vulnerability mechanics

References

15

News mentions

0

No linked articles in our index yet.