A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade ipa-debugsourceUpgrade ipa-server-trust-adUpgrade ipa-debuginfoUpgrade ipa-selinux-nfastUpgrade ipa-client-commonUpgrade ipa-server-encrypted-dnsUpgrade ipa-server-debuginfoUpgrade ipa-server-commonUpgrade ipa-client-debuginfoUpgrade python3-ipalibUpgrade ipa-server-dnsNo solution existsUpgrade ipa-client-sambaUpgrade python3-ipaserverUpgrade python3-ipatestsUpgrade ipa-client-epnUpgrade ipa-selinux-lunaUpgrade python3-ipaclientUpgrade ipa-serverUpgrade ipa-client-encrypted-dnsUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-selinuxUpgrade ipa-clientUpgrade ipa-common | Sep 11, 2026 | Sep 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub