Lucene search

K
cvelistApacheCVELIST:CVE-2016-8751
HistoryJun 14, 2017 - 5:00 p.m.

CVE-2016-8751

2017-06-1417:00:00
apache
www.cve.org

5.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.

CNA Affected

[
  {
    "product": "Apache Ranger",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "0.5.x"
      },
      {
        "status": "affected",
        "version": "0.6.0 - 0.6.2"
      }
    ]
  }
]

5.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

Related for CVELIST:CVE-2016-8751