CVE-2014-7850: XSS
An XSS flaw was reported in FreeIPA 4.x that could allow an administrator with lower privileges (such as sudo rights) to escalate their privileges to full administrator.
Earlier versions of FreeIPA/IPA do not suffer from this flaw.
Statement:
This issue did not affect the versions of IPA as shipped with Red Hat Enterprise Linux 6 or 7 as they do not include the vulerable Web UI code.
Other sources
Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7850?
The severity of CVE-2014-7850 is high due to its potential to allow privilege escalation for unauthorized users.
How do I fix CVE-2014-7850?
To fix CVE-2014-7850, upgrade FreeIPA to version 4.1.2 or later where the vulnerability has been addressed.
What versions of FreeIPA are affected by CVE-2014-7850?
FreeIPA versions from 4.0.0 to 4.1.1 are affected by CVE-2014-7850.
What type of vulnerability is CVE-2014-7850?
CVE-2014-7850 is an XSS (Cross-Site Scripting) vulnerability that affects FreeIPA.
Who can exploit CVE-2014-7850?
An administrator with lower privileges, such as sudo rights, can exploit CVE-2014-7850 to escalate privileges to full administrator.