CVE-2024-45478

MEDIUM

Apache Ranger 2.4.0 - Stored Cross-Site Scripting in Edit Service Page

Title source: llm
STIX 2.1

Description

Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.

References (2)

Core 2

Scores

CVSS v3 4.8
EPSS 0.0067
EPSS Percentile 71.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
apache/ranger 2.4.0 - 2.5.0
org.apache.ranger/ranger 0 - 2.5.0Maven
Published Jan 21, 2025
Tracked Since Feb 18, 2026