Back

MEDIUM

ipa: Session not terminated after logout

Published Sep 17, 2019

Description

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

Affected products

Remediation

Red Hat statement

In order to exploit this flaw, an attacker would need to obtain a user's session cookie after the user has logged out but before the server-side credential cache expires. Typically, this will not be possible because browsers protect the cookie while it is valid and delete it immediately as instructed by the server on logout. In order to be exposed to this vulnerability, one would need to be accessing FreeIPA in a non-standard fashion with an insecure web browser or a client application that stores and shares excessive debugging information. Most users of FreeIPA will not be at risk from this flaw.

Weaknesses (1)

References (5)

Change history (6)
  1. MITRE
    • CVSS severity changed from LOW to MEDIUM
    • CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N to CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
    • CVSS score changed from 1.8 to 5.6
  2. REDHAT
    • CVSS severity changed from MEDIUM to LOW
    • CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N to CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
    • CVSS score changed from 5.6 to 1.8
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 17, 2019
Updated Aug 5, 2024
Reserved Aug 10, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 17, 2019