Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.
https://fedorahosted.org/freeipa/ticket/4742
https://bugzilla.redhat.com/show_bug.cgi?id=1165280
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/144848.html