GHSA-xp4g-5xj6-6vpr
Dashboard / Vulnerabilities / GHSA-xp4g-5xj6-6vpr
Summary: Apache Drill vulnerable to Cross-site Scripting
Details: In Apache Drill 1.11.0 and earlier, when submitting form from Query page, users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may obtain this information from Profile page afterwards.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-12630, https://github.com/apache/drill, https://lists.apache.org/thread.html/608658a55d09e16542db41121a0a972c97448214cdc04071fd4db923@%3Cdev.drill.apache.org%3E
Affected packages
Package
Name: org.apache.drill:drill-common
Purl: pkg:maven/org.apache.drill/drill-common
Affected ranges
Type: ECOSYSTEM
Events:
