Description
Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.
Affected products
- Apache Software Foundation / Apache Ranger0.5.x – 0.5.x
- Apache Software Foundation / Apache Ranger0.6.0 - 0.6.2 – 0.6.0 - 0.6.2