QID 981020
QID 981020: Java (maven) Security Update for org.apache.ranger:ranger (GHSA-j84c-j8qm-g47r)
The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid username.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-j84c-j8qm-g47r for updates pertaining to this vulnerability.
Vendor References
- GHSA-j84c-j8qm-g47r -
github.com/advisories/GHSA-j84c-j8qm-g47r
CVEs related to QID 981020
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j84c-j8qm-g47r | org.apache.ranger:ranger |
|