Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Ranger
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11778 1 Apache 1 Ranger 2020-08-24 6.5 MEDIUM 8.8 HIGH
UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0
CVE-2016-2174 1 Apache 1 Ranger 2016-06-14 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.
CVE-2016-0735 1 Apache 1 Ranger 2016-04-19 6.5 MEDIUM 8.8 HIGH
Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy.
CVE-2015-0266 1 Apache 1 Ranger 2016-04-13 6.5 MEDIUM 7.1 HIGH
The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to module URLs.