Vulnerability Details CVE-2016-8746
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.6%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2016-8746
-
cpe:2.3:a:apache:ranger:0.4.0
-
cpe:2.3:a:apache:ranger:0.4.1
-
cpe:2.3:a:apache:ranger:0.5.0
-
cpe:2.3:a:apache:ranger:0.5.1
-
cpe:2.3:a:apache:ranger:0.5.2
-
cpe:2.3:a:apache:ranger:0.5.3
-
cpe:2.3:a:apache:ranger:0.6.0
-
cpe:2.3:a:apache:ranger:0.6.1
-
cpe:2.3:a:apache:ranger:0.6.2