CVE-2016-8751

CVSS v3.0 4.8 (Medium)
48% Progress
CVSS v2.0 3.5 (Low)
35% Progress
EPSS 0.04 % (17th)
0.04% Progress
Affected Products 1
Advisories 1

Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2017-06-14 17:29:00
(7 years ago)
Updated Date
2019-03-01 20:42:58
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Ranger prior 0.6.3 version cpe:2.3:a:apache:ranger < 0.6.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...