Vulnerabilities
Vulnerable Software
Apache:  >> Ranger  >> 0.6.2  Security Vulnerabilities
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-03-03
UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0
CVSS Score
8.8
EPSS Score
0.01
Published
2018-10-05
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
CVSS Score
5.9
EPSS Score
0.005
Published
2017-06-14
Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.
CVSS Score
4.8
EPSS Score
0.002
Published
2017-06-14
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
CVSS Score
9.8
EPSS Score
0.009
Published
2017-06-14
In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.
CVSS Score
5.9
EPSS Score
0.003
Published
2017-06-14


Contact Us

Shodan ® - All rights reserved