CVE-2016-5395: XSS
Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5395?
CVE-2016-5395 is categorized as a high severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2016-5395?
To fix CVE-2016-5395, upgrade Apache Ranger to version 0.6.1 or later.
What causes the CVE-2016-5395 vulnerability?
CVE-2016-5395 is caused by improper validation of user input in the create user functionality of Apache Ranger.
Who is affected by CVE-2016-5395?
CVE-2016-5395 affects authenticated administrators using versions of Apache Ranger prior to 0.6.1.
What are the potential impacts of CVE-2016-5395?
The potential impacts of CVE-2016-5395 include the ability for attackers to inject arbitrary web scripts or HTML into the application.