CVE-2016-8751: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.
References
Detect and mitigate CVE-2016-8751 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →