CVE-2016-8746

CWE-4264 documents4 sources
Severity
5.9MEDIUM
EPSS
0.5%
top 32.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14
Latest updateOct 17

Description

Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Apache Ranger policy engine incorrectly matches paths in certain conditions2018-10-17
GHSA
Apache Ranger policy engine incorrectly matches paths in certain conditions2018-10-17
CVEList
CVE-2016-8746: Apache Ranger before 02017-06-14