CVE-2024-45478
Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service Page
4.8
MEDIUM
CVSS 3.1
EPSS 0.67%
Description
Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
How to fix CVE-2024-45478
To remediate CVE-2024-45478, upgrade the affected package to a fixed version below.
- Maven/org.apache.ranger:ranger—upgrade to 2.5.0 or later
Is CVE-2024-45478 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.5.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |