Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2024-45479

Disclosure Date: January 21, 2025 (last updated February 27, 2025)
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
0
Attacker Value
Unknown

CVE-2024-45478

Disclosure Date: January 21, 2025 (last updated February 27, 2025)
Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
0
Attacker Value
Unknown

CVE-2022-45048

Disclosure Date: May 05, 2023 (last updated February 24, 2025)
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Attacker Value
Unknown

CVE-2021-40331

Disclosure Date: May 05, 2023 (last updated February 24, 2025)
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.
Attacker Value
Unknown

CVE-2019-12397

Disclosure Date: August 08, 2019 (last updated November 08, 2023)
Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.
0
Attacker Value
Unknown

CVE-2018-17873

Disclosure Date: October 23, 2018 (last updated November 27, 2024)
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.
0
Attacker Value
Unknown

CVE-2018-11778

Disclosure Date: October 05, 2018 (last updated November 08, 2023)
UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0
0
Attacker Value
Unknown

CVE-2017-5711

Disclosure Date: November 21, 2017 (last updated November 26, 2024)
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
Attacker Value
Unknown

CVE-2017-5712

Disclosure Date: November 21, 2017 (last updated November 26, 2024)
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
Attacker Value
Unknown

CVE-2016-6815

Disclosure Date: October 13, 2017 (last updated November 26, 2024)
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
0