CVE-2022-45048
published 2023-05-05CVE-2022-45048: Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache…
PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.13%
62.7th percentile
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ranger | — | — |
| apache_software_foundation | apache_ranger | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Ranger code execution vulnerability in policy expressions
ghsa·2023-07-06
CVE-2022-45048 [HIGH] CWE-74 Apache Ranger code execution vulnerability in policy expressions
Apache Ranger code execution vulnerability in policy expressions
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
OSV
Apache Ranger code execution vulnerability in policy expressions
osv·2023-07-06
CVE-2022-45048 [HIGH] Apache Ranger code execution vulnerability in policy expressions
Apache Ranger code execution vulnerability in policy expressions
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-05
Published