Apache Software Foundation Apache Ranger vulnerabilities
22 known vulnerabilities affecting apache_software_foundation/apache_ranger.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH5MEDIUM8
Vulnerabilities
Page 2 of 2
CVE-2016-8751P4MEDIUMCVSS 4.8v0.5.xv0.6.0 - 0.6.22017-06-14
CVE-2016-8751 [MEDIUM] CWE-79 CVE-2016-8751: Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom po
Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.
nvd
CVE-2024-45478P4MEDIUMCVSS 4.8≥ 2.4.0, < 2.5.02025-01-21
CVE-2024-45478 [MEDIUM] CWE-79 CVE-2024-45478: Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Us
Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0.
Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
nvd
← Previous2 / 2