First published: Mon Sep 26 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ranger | <=0.5.0 | |
Apache Ranger | =0.5.1 | |
Apache Ranger | =0.5.2 | |
Apache Ranger | =0.5.3 | |
Apache Ranger | =0.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5395 is categorized as a high severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2016-5395, upgrade Apache Ranger to version 0.6.1 or later.
CVE-2016-5395 is caused by improper validation of user input in the create user functionality of Apache Ranger.
CVE-2016-5395 affects authenticated administrators using versions of Apache Ranger prior to 0.6.1.
The potential impacts of CVE-2016-5395 include the ability for attackers to inject arbitrary web scripts or HTML into the application.