CVE Database
/

CVE-2016-8751

Back to search

CVE-2016-8751

Published: Jun 14, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.

VendorProductVersions

Apache Software Foundation

Apache Ranger

affected
0.5.x
affected
0.6.0 - 0.6.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now