Candidate: CVE-2014-7850 PublicDate: 2014-11-28 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7850 https://fedorahosted.org/freeipa/ticket/4742 Description: Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation. Ubuntu-Description: Notes: ebarretto> FreeIPA 4.x issue, marking Trusty as not affected Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_freeipa: upstream_freeipa: released (4.1.2) lucid_freeipa: DNE precise_freeipa: ignored (reached end-of-life) precise/esm_freeipa: DNE (precise was needs-triage) trusty_freeipa: not-affected trusty/esm_freeipa: not-affected utopic_freeipa: ignored (reached end-of-life) vivid_freeipa: ignored (reached end-of-life) vivid/stable-phone-overlay_freeipa: DNE vivid/ubuntu-core_freeipa: DNE wily_freeipa: not-affected (4.1.4-1) xenial_freeipa: not-affected (4.1.4-1) yakkety_freeipa: not-affected (4.1.4-1) zesty_freeipa: not-affected (4.1.4-1) artful_freeipa: not-affected (4.1.4-1) bionic_freeipa: not-affected (4.1.4-1) cosmic_freeipa: not-affected (4.1.4-1) devel_freeipa: not-affected (4.1.4-1)