First published: Mon Apr 11 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary web script or HTML via the HTTP User-Agent header.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ranger | <=0.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0265 is considered to have a medium severity due to its potential for cross-site scripting attacks.
To fix CVE-2015-0265, upgrade to Apache Ranger version 0.5.0 or later.
Users of Apache Ranger versions prior to 0.5.0 are impacted by CVE-2015-0265.
CVE-2015-0265 enables remote attackers to perform cross-site scripting (XSS) attacks.
CVE-2015-0265 affects the Policy Admin Tool in Apache Ranger.