CVE-2024-45478

Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*

History

28 May 2025, 20:45

Type Values Removed Values Added
CPE cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*
CWE CWE-79
First Time Apache
Apache ranger
References () https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger - () https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/01/21/3 - () http://www.openwall.com/lists/oss-security/2025/01/21/3 - Mailing List, Third Party Advisory

22 Jan 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
Summary
  • (es) Vulnerabilidad de XSS almacenado en la página de edición de servicios de la interfaz de usuario de Apache Ranger en la versión 2.4.0 de Apache Ranger. Se recomienda a los usuarios que actualicen a la versión 2.5.0 de Apache Ranger, que soluciona este problema.

21 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 22:15

Updated : 2025-05-28 20:45


NVD link : CVE-2024-45478

Mitre link : CVE-2024-45478

CVE.ORG link : CVE-2024-45478


JSON object : View

Products Affected

apache

  • ranger
CWE
CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')