{"id":"GHSA-v7mf-qgxf-qmvf","summary":"Apache Ranger admin users can store some arbitrary javascript code to be executed when normal users login and access policies","details":"Apache Ranger before 0.6.is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.","aliases":["CVE-2016-8751"],"modified":"2023-11-01T04:47:13.257980Z","published":"2018-10-17T17:21:54Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:57:10Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8751"},{"type":"WEB","url":"https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v7mf-qgxf-qmvf"},{"type":"WEB","url":"http://www.securityfocus.com/bid/99067"}],"affected":[{"package":{"name":"org.apache.ranger:ranger","ecosystem":"Maven","purl":"pkg:maven/org.apache.ranger/ranger"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.3"}]}],"versions":["0.6.0","0.6.1","0.6.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-v7mf-qgxf-qmvf/GHSA-v7mf-qgxf-qmvf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}