QID 981311
QID 981311: Java (maven) Security Update for org.apache.ranger:ranger (GHSA-4rjf-mxfm-98h5)
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4rjf-mxfm-98h5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-4rjf-mxfm-98h5 -
github.com/advisories/GHSA-4rjf-mxfm-98h5
CVEs related to QID 981311
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4rjf-mxfm-98h5 | org.apache.ranger:ranger |
|