Executive brief
FreeIPA is an identity and access management system used by organizations to manage user authentication and authorization. An attacker can craft a link that redirects users to a malicious website after they complete a password reset, enabling phishing attacks that steal credentials or trick users into downloading malware.
Technical details
The vulnerability is an open redirect (CWE-601) in reset_password.html. The page parses the 'url' query string parameter and directly passes it to window.location without validation or allowlisting, enabling arbitrary client-side redirection after password reset. The 'delay' parameter allows an attacker to optionally delay the redirect. Attack requires user interaction (following a crafted link), and exploitation is typically used for phishing or drive-by download attacks. Red Hat recommends eliminating arbitrary redirects, allowlisting same-origin paths, or using server-generated signed tokens instead of raw URLs.
Affected products
- Red Hat FreeIPA
Timeline
- 2026-09-02: disclosed