Description
Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.
Remediation
References
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
http://www.securityfocus.com/bid/99067
Related Vulnerabilities
CVE-2021-4264 Vulnerability in maven package org.webjars.npm:dustjs-linkedin
CVE-2020-16042 Vulnerability in maven package org.webjars.npm:electron
CVE-2018-1309 Vulnerability in maven package org.apache.nifi:nifi-standard-processors
CVE-2023-28676 Vulnerability in maven package org.jenkins-ci.plugins:convert-to-pipeline
CVE-2020-27219 Vulnerability in maven package org.eclipse.hawkbit:hawkbit-update-server