Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0.
Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
CVSS
No CVSS.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2025/01/21/3 | Mailing List Third Party Advisory |
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger | Vendor Advisory |
Configurations
History
28 May 2025, 20:45
Type | Values Removed | Values Added |
---|---|---|
References | () https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger - Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2025/01/21/3 - Mailing List, Third Party Advisory | |
First Time |
Apache ranger
Apache |
|
CPE | cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:* | |
CWE | CWE-79 |
22 Jan 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE |
21 Jan 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-21 22:15
Updated : 2025-06-10 09:15
NVD link : CVE-2024-45478
Mitre link : CVE-2024-45478
JSON object : View
Products Affected
apache
- ranger
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')