Логотип exploitDog
bind:"CVE-2019-14867" OR bind:"CVE-2019-10195"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-14867" OR bind:"CVE-2019-10195"

Количество 11

Количество 11

oracle-oval логотип

ELSA-2020-0378

около 6 лет назад

ELSA-2020-0378: ipa security and bug fix update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2019-14867

около 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2019-14867

больше 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-14867

около 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-14867

около 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x ve ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-10195

около 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-10195

около 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2019-10195

около 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-10195

около 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x ve ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w4q7-f34x-vpgc

больше 3 лет назад

FreeIPA logs passwords embedded in commands in calls using batch

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-7hpj-hfcr-5qwm

около 4 лет назад

Code injection in FreeIPA

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-0378

ELSA-2020-0378: ipa security and bug fix update (IMPORTANT)

около 6 лет назад
ubuntu логотип
CVE-2019-14867

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
3%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-14867

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-14867

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
3%
Низкий
около 6 лет назад
debian логотип
CVE-2019-14867

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x ve ...

CVSS3: 8.8
3%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 6.5
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 5.7
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 6.5
1%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x ve ...

CVSS3: 6.5
1%
Низкий
около 6 лет назад
github логотип
GHSA-w4q7-f34x-vpgc

FreeIPA logs passwords embedded in commands in calls using batch

CVSS3: 5.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-7hpj-hfcr-5qwm

Code injection in FreeIPA

CVSS3: 8.8
3%
Низкий
около 4 лет назад

Уязвимостей на страницу