Vulnerabilities
Vulnerable Software
Apache:  >> Ranger  >> 1.1.0  Security Vulnerabilities
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVSS Score
7.5
EPSS Score
0.006
Published
2026-08-10
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVSS Score
6.5
EPSS Score
0.006
Published
2026-08-10
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVSS Score
7.3
EPSS Score
0.006
Published
2026-08-10
SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue.
CVSS Score
9.8
EPSS Score
0.007
Published
2026-08-10
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVSS Score
9.8
EPSS Score
0.007
Published
2026-08-10
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVSS Score
9.8
EPSS Score
0.013
Published
2026-08-10
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVSS Score
9.8
EPSS Score
0.012
Published
2026-08-10
Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVSS Score
9.8
EPSS Score
0.012
Published
2026-08-10
Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVSS Score
7.5
EPSS Score
0.007
Published
2026-08-10
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.
CVSS Score
9.8
EPSS Score
0.026
Published
2026-08-10


Contact Us

Shodan ® - All rights reserved