Apache / Ranger
31 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-28672 | Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder | CRITICAL | 9.8 | Aug 10, 2026 |
| CVE-2026-32227 | Apache Ranger: SQL Injection vulnerability in lookup functionality | CRITICAL | 9.8 | Aug 10, 2026 |
| CVE-2026-40920 | Apache Ranger: Privilege Escalation via URL Parameter | CRITICAL | 9.8 | Aug 10, 2026 |
| CVE-2026-42537 | Apache Ranger: Remote Code Execution via JDBC URL Injection | CRITICAL | 9.8 | Aug 10, 2026 |
| CVE-2026-44416 | Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation | CRITICAL | 9.8 | Aug 10, 2026 |
| CVE-2026-55799 | Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator | CRITICAL | 9.8 | Aug 10, 2026 |
| CVE-2026-55814 | Apache Ranger: Download APIs expose plugin data without authentication | HIGH | 7.5 | Aug 10, 2026 |
| CVE-2026-65942 | Apache Ranger: Clients accept TLS certificates issued for other hostnames | HIGH | 7.5 | Aug 10, 2026 |
| CVE-2026-65945 | Apache Ranger: Logs contain replayable JWT bearer tokens | MEDIUM | 6.5 | Aug 10, 2026 |
| CVE-2026-65948 | Apache Ranger: UnixAuth lacks brute-force protection | HIGH | 7.3 | Aug 10, 2026 |
| CVE-2025-59060 | Apache Ranger: Hostname verification bypass in NiFiRegistryClient | MEDIUM | 5.3 | Mar 3, 2026 |
| CVE-2025-59059 | Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator | CRITICAL | 9.8 | Mar 3, 2026 |
| CVE-2024-55532 | Apache Ranger: Improper Neutralization of Formula Elements in a CSV File | CRITICAL | 9.8 | Mar 3, 2025 |
| CVE-2024-45479 | Apache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhost | CRITICAL | 9.1 | Jan 21, 2025 |
| CVE-2024-45478 | Apache Ranger: Stored XSS in Edit Service page - Add logic to validate user input | MEDIUM | 4.8 | Jan 21, 2025 |
| CVE-2021-40331 | Permissions problem in the Apache Ranger Hive Plugin | HIGH | 8.1 | May 5, 2023 |
| CVE-2022-45048 | Apache Ranger: code execution vulnerability in policy expressions | HIGH | 8.8 | May 5, 2023 |
| CVE-2019-12397 | Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger w… | MEDIUM | 6.1 | Aug 8, 2019 |
| CVE-2018-11778 | UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 shoul… | HIGH | 8.8 | Oct 5, 2018 |
| CVE-2016-6815 | In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role. | MEDIUM | 6.5 | Oct 13, 2017 |
| CVE-2017-7677 | In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table. | MEDIUM | 5.9 | Jun 14, 2017 |
| CVE-2017-7676 | Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended… | CRITICAL | 9.8 | Jun 14, 2017 |
| CVE-2016-8751 | Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javas… | MEDIUM | 4.8 | Jun 14, 2017 |
| CVE-2016-8746 | Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to t… | MEDIUM | 5.9 | Jun 14, 2017 |
| CVE-2016-5395 | Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated ad… | MEDIUM | 4.8 | Sep 26, 2016 |
Showing 1 to 25 of 31 CVEs