CVE-2016-8751
medium
CVSS v3
4.8
CVSS v2
3.5
VIR risk
4.8
Description
Apache Ranger admin users can store some arbitrary javascript code to be executed when normal users login and access policies
Predictions
Exploit likelihood
58%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@apache.org — https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.ranger:ranger | <0.6.3 | 0.6.3 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| apache | ranger | {"endExcluding":"0.6.3"} | 0.6.3 |
References
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.