Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-41743 | Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service Page |
Github GHSA |
GHSA-vrx2-mgr9-v67h | Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service Page |
Tue, 10 Jun 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Wed, 28 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache ranger |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache ranger |
Wed, 22 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 21 Jan 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Jan 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. | |
| Title | Apache Ranger: Stored XSS in Edit Service page - Add logic to validate user input | |
| Weaknesses | CWE-20 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-06-10T09:05:27.590Z
Reserved: 2024-08-29T14:30:58.496Z
Link: CVE-2024-45478
Updated: 2025-01-21T22:02:48.006Z
Status : Modified
Published: 2025-01-21T22:15:12.137
Modified: 2025-06-10T09:15:22.687
Link: CVE-2024-45478
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA