Vulnerability Description
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may obtain this information from Profile page afterwards.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Drill | <= 1.11.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/608658a55d09e16542db41121a0a972c97448214cdc
- https://lists.apache.org/thread.html/608658a55d09e16542db41121a0a972c97448214cdc
FAQ
What is CVE-2017-12630?
CVE-2017-12630 is a vulnerability with a CVSS score of 5.4 (MEDIUM). In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting spe...
How severe is CVE-2017-12630?
CVE-2017-12630 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-12630?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Drill.