CVE-2017-12630: XSS
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may obtain this information from Profile page afterwards.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-12630?
CVE-2017-12630 is a vulnerability in Apache Drill 1.11.0 and earlier that allows users to pass arbitrary script or HTML, which can have unintended effects on the Profile page.
How severe is CVE-2017-12630?
CVE-2017-12630 has a severity keyword of 'medium' and a severity value of 5.4.
How does CVE-2017-12630 affect Apache Drill?
CVE-2017-12630 affects Apache Drill versions 1.11.0 and earlier.
What is the CWE ID for CVE-2017-12630?
The CWE ID for CVE-2017-12630 is 79.
Is there a fix available for CVE-2017-12630?
Yes, updating Apache Drill to a version higher than 1.11.0 will fix CVE-2017-12630.