First published: Tue Nov 18 2014(Updated: )
An XSS flaw was reported in FreeIPA 4.x that could allow an administrator with lower privileges (such as sudo rights) to escalate their privileges to full administrator. Earlier versions of FreeIPA/IPA do not suffer from this flaw. Statement: This issue did not affect the versions of IPA as shipped with Red Hat Enterprise Linux 6 or 7 as they do not include the vulerable Web UI code.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat FreeIPA | >=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1165280 is considered to be high due to the potential for privilege escalation.
To fix REDHAT-BUG-1165280, update FreeIPA to a version earlier than 4.0 or apply any available patches from the vendor.
FreeIPA versions starting from 4.0 are affected by REDHAT-BUG-1165280.
Administrators with lower privileges who use FreeIPA 4.x may be at risk for privilege escalation due to REDHAT-BUG-1165280.
Currently, the recommended approach to mitigate REDHAT-BUG-1165280 is to update to a non-vulnerable version of FreeIPA.