PT-2023-14577 · Apache · Apache Ranger

·

CVE-2022-45048

·

Published

2023-05-05

·

Updated

2024-10-15

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Ranger version 2.3.0
Description The issue allows authenticated users with appropriate privileges to create policies having expressions that can exploit a code execution vulnerability.
Recommendations For Apache Ranger version 2.3.0, update to version 2.4.0 to resolve the issue.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45048
GHSA-89GW-CFFJ-MQG9

Affected Products

Apache Ranger