CVE-2024-45478

Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*

History

10 Jun 2025, 09:15

Type Values Removed Values Added
CWE CWE-20

28 May 2025, 20:45

Type Values Removed Values Added
CWE CWE-79
First Time Apache
Apache ranger
References () https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger - () https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/01/21/3 - () http://www.openwall.com/lists/oss-security/2025/01/21/3 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*

22 Jan 2025, 19:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de XSS almacenado en la página de edición de servicios de la interfaz de usuario de Apache Ranger en la versión 2.4.0 de Apache Ranger. Se recomienda a los usuarios que actualicen a la versión 2.5.0 de Apache Ranger, que soluciona este problema.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8

21 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 22:15

Updated : 2025-06-10 09:15


NVD link : CVE-2024-45478

Mitre link : CVE-2024-45478

CVE.ORG link : CVE-2024-45478


JSON object : View

Products Affected

apache

  • ranger
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')