https://seclists.org/oss-sec/2025/q1/37: CVE-2024-45478: Apache Ranger: Stod XSS in Edit Service page - Add logic to validate user input
Published Jan 21, 2025
·Updated
Affected Software
1 affected component
Apache Ranger<2.5.0
Frequently Asked Questions
1
What is the severity of CVE-2024-45478?
The severity of CVE-2024-45478 is classified as moderate.
2
Which versions are affected by CVE-2024-45478?
CVE-2024-45478 affects Apache Ranger version 2.4.0 and earlier.
3
How do I fix CVE-2024-45478?
To fix CVE-2024-45478, upgrade to Apache Ranger version 2.5.0.
4
What is the nature of the vulnerability in CVE-2024-45478?
CVE-2024-45478 is a stored XSS vulnerability found in the Edit Service page of the Apache Ranger UI.
5
Who identified the CVE-2024-45478 vulnerability?
The CVE-2024-45478 vulnerability was credited to Gyujin.