ipa: Session not terminated after logout
Published Sep 17, 2019
4.4
MEDIUMCVSS 3.1
EPSS 0.34%
Description
A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.
Affected products
-
- Version FreeIPA versions 4.5.0 and laterStatusaffectedConstraints-
- Version
Configuration 2
- 7.0
- 8.0
No data.
Red Hat Enterprise Linux 6
ipa
Not affected
Red Hat Enterprise Linux 7
ipa
Fix deferred
Red Hat Enterprise Linux 8
idm:DL1/ipa
Fix deferred
Red Hat Enterprise Linux 8
idm:client/ipa
Not affected
Red Hat Virtualization 4
redhat-virtualization-host
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ipa | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ipa | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | idm:DL1/ipa | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | idm:client/ipa | Not affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In order to exploit this flaw, an attacker would need to obtain a user's session cookie after the user has logged out but before the server-side credential cache expires. Typically, this will not be possible because browsers protect the cookie while it is valid and delete it immediately as instructed by the server on logout. In order to be exposed to this vulnerability, one would need to be accessing FreeIPA in a non-standard fashion with an insecure web browser or a client application that stores and shares excessive debugging information. Most users of FreeIPA will not be at risk from this flaw.
References (5)
- https://access.redhat.com/security/cve/CVE-2019-14826 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1746944 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14826 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14826
- https://www.cve.org/CVERecord?id=CVE-2019-14826
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-14826 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1746944 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14826 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-14826 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-14826 |
Change history (6)
- MITRE
- CVSS severity changed from LOW to
MEDIUM LOW → MEDIUM
- CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N to
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N → CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
- CVSS score changed from 1.8 to
5.6 1.8 → 5.6
- CVSS severity changed from LOW to
MEDIUM
- REDHAT
- CVSS severity changed from MEDIUM to
LOW MEDIUM → LOW
- CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N to
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N → CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
- CVSS score changed from 5.6 to
1.8 5.6 → 1.8
- CVSS severity changed from MEDIUM to
LOW