Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14826

Опубликовано: 17 сент. 2019
Источник: debian
EPSS Низкий

Описание

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freeipaunfixedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1746944

  • Introduced by https://pagure.io/freeipa/c/b895f4a34bcbd0b1787d2bfc1db25f34c3584b9c

  • due to fix for https://fedorahosted.org/freeipa/ticket/6682.

  • https://bugzilla.redhat.com/show_bug.cgi?id=1746944#c12

  • Negligible security impact

EPSS

Процентиль: 30%
0.00113
Низкий

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 6 лет назад

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

CVSS3: 1.8
redhat
больше 6 лет назад

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

CVSS3: 4.4
nvd
больше 6 лет назад

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

CVSS3: 4.4
github
больше 3 лет назад

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

CVSS3: 6
fstec
больше 6 лет назад

Уязвимость сервера FreeIPA, связанная с неверным сроком действия сеанса, позволяющая нарушителю получить доступ к сеансу

EPSS

Процентиль: 30%
0.00113
Низкий