cbcvebase.
CVE-2016-8751
published 2017-06-14

CVE-2016-8751: Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary…

medium4.8CVSS 3.0
AVNACLPRHUIRSCCLILAN
Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheranger< 0.6.30.6.3
apache_software_foundationapache_ranger
apache_software_foundationapache_ranger