CVE-2016-0735

CWE-2644 documents4 sources
Severity
8.8HIGH
EPSS
0.1%
top 65.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 11
Latest updateMay 17

Description

Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

Mavenorg.apache.ranger:ranger0.5.00.5.2
NVDapache/ranger0.5.0, 0.5.1+1

🔴Vulnerability Details

3
GHSA
Apache Ranger Access Restriction Bypass2022-05-17
OSV
Apache Ranger Access Restriction Bypass2022-05-17
CVEList
CVE-2016-0735: Apache Ranger 02016-04-11