CVE-2018-11778

Severity
8.8HIGH
EPSS
1.1%
top 21.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 5
Latest updateOct 17

Description

UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDapache/ranger< 1.2.0

🔴Vulnerability Details

3
GHSA
UnixAuthenticationService in Apache Ranger was updated to correctly handle user input to avoid Stack-based buffer overflow2018-10-17
OSV
UnixAuthenticationService in Apache Ranger was updated to correctly handle user input to avoid Stack-based buffer overflow2018-10-17
CVEList
CVE-2018-11778: UnixAuthenticationService in Apache Ranger 12018-10-05