Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

oracle-oval логотип

ELSA-2020-0378

больше 6 лет назад

ELSA-2020-0378: ipa security and bug fix update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2019-14867

больше 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2019-14867

почти 7 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-14867

больше 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-14867

больше 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x ve ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-10195

больше 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-10195

больше 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2019-10195

больше 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-10195

больше 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x ve ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w4q7-f34x-vpgc

около 4 лет назад

FreeIPA logs passwords embedded in commands in calls using batch

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-7hpj-hfcr-5qwm

больше 4 лет назад

Code injection in FreeIPA

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-0378

ELSA-2020-0378: ipa security and bug fix update (IMPORTANT)

больше 6 лет назад
ubuntu логотип
CVE-2019-14867

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
7%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-14867

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
7%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-14867

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
7%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-14867

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x ve ...

CVSS3: 8.8
7%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 5.7
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x ve ...

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
github логотип
GHSA-w4q7-f34x-vpgc

FreeIPA logs passwords embedded in commands in calls using batch

CVSS3: 5.7
2%
Низкий
около 4 лет назад
github логотип
GHSA-7hpj-hfcr-5qwm

Code injection in FreeIPA

CVSS3: 8.8
7%
Низкий
больше 4 лет назад

Уязвимостей на страницу