PT-2014-8315 · Red Hat · Freeipa

Pvoborni

·

Publicado

2014-11-28

·

Atualizado

2015-02-17

·

CVE-2014-7850

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FreeIPA versions 4.0 through 4.1.1 FreeIPA version 4.1.2 is not affected, but all versions prior to 4.1.2 are vulnerable, so the correct representation is: FreeIPA versions prior to 4.1.2
Description A cross-site scripting (XSS) issue exists in the Web UI, allowing remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.
Recommendations For FreeIPA versions prior to 4.1.2, update to version 4.1.2 or later to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-7850

Produtos afetados

Freeipa