[MAVEN:GHSA-4RJF-MXFM-98H5] SQL injection vulnerability in the policy admin tool in Apache Ranger

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.

Package Affected Version
pkg:maven/org.apache.ranger/ranger < 0.5.3
Package Fixed Version
pkg:maven/org.apache.ranger/ranger = 0.5.3
ID
MAVEN:GHSA-4RJF-MXFM-98H5
Severity
high
URL
https://github.com/advisories/GHSA-4rjf-mxfm-98h5
Published
2018-10-17T17:21:29
(6 years ago)
Modified
2023-01-09T05:02:41
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.ranger/ranger org.apache.ranger ranger < 0.5.3
Fixed pkg:maven/org.apache.ranger/ranger org.apache.ranger ranger = 0.5.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...