Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2024-45479
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0.
Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
0
Attacker Value
Unknown
CVE-2024-45478
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0.
Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
0
Attacker Value
Unknown
CVE-2022-45048
Disclosure Date: May 05, 2023 (last updated February 24, 2025)
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
0
Attacker Value
Unknown
CVE-2021-40331
Disclosure Date: May 05, 2023 (last updated February 24, 2025)
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled
This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.
0
Attacker Value
Unknown
CVE-2019-12397
Disclosure Date: August 08, 2019 (last updated November 08, 2023)
Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.
0
Attacker Value
Unknown
CVE-2018-17873
Disclosure Date: October 23, 2018 (last updated November 27, 2024)
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.
0
Attacker Value
Unknown
CVE-2018-11778
Disclosure Date: October 05, 2018 (last updated November 08, 2023)
UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0
0
Attacker Value
Unknown
CVE-2017-5711
Disclosure Date: November 21, 2017 (last updated November 26, 2024)
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
0
Attacker Value
Unknown
CVE-2017-5712
Disclosure Date: November 21, 2017 (last updated November 26, 2024)
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
0
Attacker Value
Unknown
CVE-2016-6815
Disclosure Date: October 13, 2017 (last updated November 26, 2024)
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
0