Description
Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies.
Remediation
References
http://www.securityfocus.com/bid/92577
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2018-8014 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2021-46089 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2020-2280 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2020-7609 Vulnerability in npm package node-rules
CVE-2016-4431 Vulnerability in maven package org.apache.struts:struts2-core