VulnerabilityModified
CVE-2016-8746
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
MEDIUM 5.9EPSS 2.73%
Does this matter?
Lower severity and a low EPSS score (2.73%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.73% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-426
- Affected
- apache/ranger
- Source
- security@apache.org
References
- http://www.securityfocus.com/bid/95998Third Party Advisory, VDB Entry
- https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+RangerRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/95998Third Party Advisory, VDB Entry
- https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+RangerRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.