First published: Tue Nov 18 2014(Updated: )
An XSS flaw was reported in FreeIPA 4.x that could allow an administrator with lower privileges (such as sudo rights) to escalate their privileges to full administrator. Earlier versions of FreeIPA/IPA do not suffer from this flaw. Statement: This issue did not affect the versions of IPA as shipped with Red Hat Enterprise Linux 6 or 7 as they do not include the vulerable Web UI code.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Freeipa Freeipa | =4.0.0 | |
Freeipa Freeipa | =4.0.1 | |
Freeipa Freeipa | =4.0.2 | |
Freeipa Freeipa | =4.0.3 | |
Freeipa Freeipa | =4.0.4 | |
Freeipa Freeipa | =4.0.5 | |
Freeipa Freeipa | =4.1.0 | |
Freeipa Freeipa | =4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.