Apache Ranger JavaScript code injection vulnerability (CVE-2015-0265)
Apache Ranger JavaScript code injection vulnerability (CVE-2015-0265)
Release date:
Updated on:
Affected Systems:
Apache Group Ranger 0.5.x <0.5.2
Description:
Bugtraq id: 76208
CVE (CAN) ID: CVE-2015-0265
Ranger is a comprehensive data security framework for implementing, monitoring, and managing Hadoop platforms.
Apache Ranger 0.5.x <0.5.0 version Policy Admin Tool has a cross-site scripting vulnerability. Through the HTTP User-Agent header, remote users can inject Web scripts or HTML.
<* Source: Jakub Kaluzny
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
This article permanently updates the link address: