Total
31 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-59060 | 1 Apache | 1 Ranger | 2026-08-24 | N/A | 5.3 MEDIUM |
| Hostname verification bypass issue in Apache Ranger NiFiRegistryClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue. | |||||
| CVE-2026-65948 | 1 Apache | 1 Ranger | 2026-08-17 | N/A | 7.3 HIGH |
| UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option for production deployments. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |||||
| CVE-2026-65945 | 1 Apache | 1 Ranger | 2026-08-17 | N/A | 6.5 MEDIUM |
| Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |||||
| CVE-2026-42537 | 1 Apache | 1 Ranger | 2026-08-17 | N/A | 9.8 CRITICAL |
| Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |||||
| CVE-2026-40920 | 1 Apache | 1 Ranger | 2026-08-17 | N/A | 9.8 CRITICAL |
| Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |||||
| CVE-2026-32227 | 1 Apache | 1 Ranger | 2026-08-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue. | |||||
| CVE-2026-28672 | 1 Apache | 1 Ranger | 2026-08-17 | N/A | 9.8 CRITICAL |
| Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8. | |||||
| CVE-2026-44416 | 1 Apache | 1 Ranger | 2026-08-17 | N/A | 9.8 CRITICAL |
| Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |||||
| CVE-2026-55799 | 1 Apache | 1 Ranger | 2026-08-17 | N/A | 9.8 CRITICAL |
| Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |||||
| CVE-2026-55814 | 1 Apache | 1 Ranger | 2026-08-17 | N/A | 7.5 HIGH |
| Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |||||
| CVE-2026-65942 | 1 Apache | 1 Ranger | 2026-08-17 | N/A | 7.5 HIGH |
| TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |||||
| CVE-2025-59059 | 1 Apache | 1 Ranger | 2026-06-17 | N/A | 9.8 CRITICAL |
| Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue. | |||||
| CVE-2024-55532 | 1 Apache | 1 Ranger | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue. | |||||
| CVE-2024-45479 | 1 Apache | 1 Ranger | 2026-06-17 | N/A | 9.1 CRITICAL |
| SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. | |||||
| CVE-2024-45478 | 1 Apache | 1 Ranger | 2026-06-17 | N/A | 4.8 MEDIUM |
| Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. | |||||
| CVE-2022-45048 | 1 Apache | 1 Ranger | 2026-06-17 | N/A | 8.4 HIGH |
| Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0. | |||||
| CVE-2021-40331 | 1 Apache | 1 Ranger | 2026-06-17 | N/A | 8.1 HIGH |
| An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later. | |||||
| CVE-2019-12397 | 1 Apache | 1 Ranger | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix. | |||||
| CVE-2018-11778 | 1 Apache | 1 Ranger | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0 | |||||
| CVE-2017-7677 | 1 Apache | 1 Ranger | 2026-06-17 | 4.3 MEDIUM | 5.9 MEDIUM |
| In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table. | |||||
