CVE-2015-0265: XSS
Published Apr 11, 2016
·Updated
Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary web script or HTML via the HTTP User-Agent header.
Affected Software
2 affected componentsFixes available
Apache Ranger<=0.4.0
maven/org.apache.ranger:ranger<0.5.0
0.5.0
Event History
Apr 11, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:59 PM
DescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
via GitHub·03:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-0265?
CVE-2015-0265 is considered to have a medium severity due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-0265?
To fix CVE-2015-0265, upgrade to Apache Ranger version 0.5.0 or later.
3
Who is impacted by CVE-2015-0265?
Users of Apache Ranger versions prior to 0.5.0 are impacted by CVE-2015-0265.
4
What type of attack does CVE-2015-0265 enable?
CVE-2015-0265 enables remote attackers to perform cross-site scripting (XSS) attacks.
5
What component of Apache Ranger does CVE-2015-0265 affect?
CVE-2015-0265 affects the Policy Admin Tool in Apache Ranger.