Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Gyujin

#20487of 56,330
13.9Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2025-2698
4.8
2025-01-21
Apache · Apache Ranger · CVE-2024-45478
**Name of the Vulnerable Software and Affected Versions** Apache Ranger version 2.4.0 **Description** A Stored XSS issue exists in the Edit Service Page of the Apache Ranger UI. This allows for malicious script execution. Users are advised to upgrade to Apache Ranger version 2.5.0 to resolve the issue. **Recommendations** For Apache Ranger version 2.4.0, upgrade to version 2.5.0 to fix the issue. As a temporary workaround, consider restricting access to the Edit Service Page in the Apache Ranger UI until the upgrade can be applied.
PT-2025-2699
9.1
2025-01-21
Apache · Apache Ranger · CVE-2024-45479
Name of the Vulnerable Software and Affected Versions: Apache Ranger versions 2.4.0 Description: A Server-Side Request Forgery (SSRF) issue exists in the Edit Service Page of the Apache Ranger UI. Users are recommended to upgrade to version Apache Ranger 2.5.0 to resolve this issue. Recommendations: Apache Ranger version 2.4.0: Upgrade to Apache Ranger version 2.5.0 to fix the SSRF vulnerability.