CVE-2019-12397: XSS
Published Aug 8, 2019
·Updated
Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.
Affected Software
1 affected component
Apache Ranger>=0.7.0<=1.2.0
Event History
Aug 8, 2019
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-12397?
CVE-2019-12397 has a high severity rating due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2019-12397?
To fix CVE-2019-12397, upgrade your Apache Ranger to version 2.0.0 or later.
3
Which versions of Apache Ranger are affected by CVE-2019-12397?
Apache Ranger versions from 0.7.0 to 1.2.0 are affected by CVE-2019-12397.
4
What type of vulnerability is CVE-2019-12397?
CVE-2019-12397 is a cross-site scripting (XSS) vulnerability.
5
What is the impact of CVE-2019-12397?
The impact of CVE-2019-12397 includes the potential exposure of sensitive user data and session hijacking.