PT-2014-8315 · Red Hat · Freeipa

Pvoborni

·

Published

2014-11-28

·

Updated

2015-02-17

·

CVE-2014-7850

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FreeIPA versions 4.0 through 4.1.1 FreeIPA version 4.1.2 is not affected, but all versions prior to 4.1.2 are vulnerable, so the correct representation is: FreeIPA versions prior to 4.1.2
Description A cross-site scripting (XSS) issue exists in the Web UI, allowing remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.
Recommendations For FreeIPA versions prior to 4.1.2, update to version 4.1.2 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7850

Affected Products

Freeipa