QID 994849
Date Published: 2023-08-17
QID 994849: Java (Maven) Security Update for org.apache.ranger:ranger (GHSA-22v7-w6c5-v4rr)
Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-22v7-w6c5-v4rr for updates and patch information.
Vendor References
- GHSA-22v7-w6c5-v4rr -
github.com/advisories/GHSA-22v7-w6c5-v4rr
CVEs related to QID 994849
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-22v7-w6c5-v4rr | org.apache.ranger:ranger |
|