Medium severity6.5NVD Advisory· Published Nov 27, 2019· Updated Jun 17, 2026
CVE-2019-10195
CVE-2019-10195
Description
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
freeipaPyPI | >= 4.6.0, < 4.6.7 | 4.6.7 |
freeipaPyPI | >= 4.7.0, < 4.7.4 | 4.7.4 |
freeipaPyPI | >= 4.8.0, < 4.8.3 | 4.8.3 |
ipaPyPI | >= 4.6.0, < 4.6.7 | 4.6.7 |
ipaPyPI | >= 4.7.0, < 4.7.4 | 4.7.4 |
ipaPyPI | >= 4.8.0, < 4.8.3 | 4.8.3 |
Affected products
6cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- ghsa-coords2 versions
>= 4.6.0, < 4.6.7+ 1 more
- (no CPE)range: >= 4.6.0, < 4.6.7
- (no CPE)range: >= 4.6.0, < 4.6.7
- Red Hat/IPAv5Range: all IPA 4.6.x versions before 4.6.7
Patches
Vulnerability mechanics
References
15- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-w4q7-f34x-vpgcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10195ghsaADVISORY
- access.redhat.com/errata/RHBA-2019:4268nvdWEB
- access.redhat.com/errata/RHSA-2020:0378nvdWEB
- github.com/pypa/advisory-database/tree/main/vulns/freeipa/PYSEC-2019-22.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/ipa/PYSEC-2019-168.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/67SEUWJAJ5RMH5K4Q6TS2I7HIMXUGNKFghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/WLFL5XDCJ3WT6JCLCQVKHZBLHGW7PW4TghsaWEB
- pagure.io/freeipa/c/5913826a4654a115cd5ff2dbf4a2b3ad38a93081ghsaWEB
- www.freeipa.org/page/Releases/4.6.7nvdRelease NotesWEB
- www.freeipa.org/page/Releases/4.7.4nvdRelease NotesWEB
- www.freeipa.org/page/Releases/4.8.3nvdRelease NotesWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/67SEUWJAJ5RMH5K4Q6TS2I7HIMXUGNKF/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLFL5XDCJ3WT6JCLCQVKHZBLHGW7PW4T/nvd
News mentions
0No linked articles in our index yet.