First published: Thu Aug 08 2019(Updated: )
Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ranger | >=0.7.0<=1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12397 has a high severity rating due to its potential to allow cross-site scripting attacks.
To fix CVE-2019-12397, upgrade your Apache Ranger to version 2.0.0 or later.
Apache Ranger versions from 0.7.0 to 1.2.0 are affected by CVE-2019-12397.
CVE-2019-12397 is a cross-site scripting (XSS) vulnerability.
The impact of CVE-2019-12397 includes the potential exposure of sensitive user data and session hijacking.