CVE-2016-8751

Severity
4.8MEDIUM
EPSS
0.2%
top 57.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14
Latest updateOct 17

Description

Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages3 packages

NVDapache/ranger< 0.6.3
CVEListV5apache_software_foundation/apache_ranger0.5.x, 0.6.0 - 0.6.2+1

🔴Vulnerability Details

3
GHSA
Apache Ranger admin users can store some arbitrary javascript code to be executed when normal users login and access policies2018-10-17
OSV
Apache Ranger admin users can store some arbitrary javascript code to be executed when normal users login and access policies2018-10-17
CVEList
CVE-2016-8751: Apache Ranger before 02017-06-14

💬Community

1
Bugzilla
CVE-2015-8751 jasper: integer overflow in the jas_matrix_create() function2016-01-08