CVE-2024-45478

Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*

History

28 May 2025, 20:45

Type Values Removed Values Added
References () https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger - () https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/01/21/3 - () http://www.openwall.com/lists/oss-security/2025/01/21/3 - Mailing List, Third Party Advisory
First Time Apache ranger
Apache
CPE cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*
CWE CWE-79

22 Jan 2025, 19:15

Type Values Removed Values Added
CWE CWE-20

21 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 22:15

Updated : 2025-06-10 09:15


NVD link : CVE-2024-45478

Mitre link : CVE-2024-45478


JSON object : View

Products Affected

apache

  • ranger
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')