Description
Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.
Remediation
References
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
http://www.securityfocus.com/bid/99067
Related Vulnerabilities
CVE-2022-2932 Vulnerability in maven package org.webjars.npm:mobiledoc-kit
CVE-2022-24289 Vulnerability in maven package org.apache.cayenne:cayenne-server
CVE-2023-25158 Vulnerability in maven package org.geotools:gt-jdbc
CVE-2022-45400 Vulnerability in maven package org.jvnet.hudson.plugins:japex
CVE-2023-28685 Vulnerability in maven package org.jenkins-ci.plugins:absint-a3