Apache

Ranger

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 03.03.2025 16:15:38
  • Zuletzt bearbeitet 21.05.2025 16:12:57

Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.

  • EPSS 0.14%
  • Veröffentlicht 21.01.2025 22:15:12
  • Zuletzt bearbeitet 10.06.2025 09:15:23

SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.

  • EPSS 0.27%
  • Veröffentlicht 21.01.2025 22:15:12
  • Zuletzt bearbeitet 10.06.2025 09:15:22

Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.

  • EPSS 0.03%
  • Veröffentlicht 05.05.2023 08:15:09
  • Zuletzt bearbeitet 21.11.2024 07:28:40

Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.

  • EPSS 0.09%
  • Veröffentlicht 05.05.2023 08:15:08
  • Zuletzt bearbeitet 21.11.2024 06:23:52

An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled Thi...

  • EPSS 2.09%
  • Veröffentlicht 08.08.2019 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:22:45

Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.

  • EPSS 0.9%
  • Veröffentlicht 05.10.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:01

UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0

  • EPSS 0.5%
  • Veröffentlicht 13.10.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.

  • EPSS 0.89%
  • Veröffentlicht 14.06.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.

  • EPSS 0.33%
  • Veröffentlicht 14.06.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.