Apache Drill XSS Vulnerability (CVE-2017-12630)
Apache Drill XSS Vulnerability (CVE-2017-12630)
Release date:
Updated on:
Affected Systems:
Apache Group Drill <= 1.11.0
Description:
Bugtraq id: 102226
CVE (CAN) ID: CVE-2017-12630
Apache Drill is an open-source SQL query engine for Big Data Detection.
Apache Drill has a cross-site scripting vulnerability. Attackers can exploit this vulnerability to execute arbitrary script code in the user's browser in the context of the affected site. This allows attackers to steal Cookie-based authentication creden. Apache Drill 1.11.0 and earlier versions are affected.
<* Source: Sanjog Panda
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apache.org/
Https://lists.apache.org/thread.html/608658a55d09e16542db41121a0a972c97448214cdc04071fd4db923@%3Cdev.drill.apache.org%3E