CVE-2025-59060

CWE-2975 documents5 sources
Severity
5.3MEDIUM
EPSS
0.1%
top 66.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3

Description

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

3
CVEList
Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient2026-03-03
OSV
Apache Ranger Vulnerable to Improper Validation of Certificate with Host Mismatch2026-03-03
GHSA
Apache Ranger Vulnerable to Improper Validation of Certificate with Host Mismatch2026-03-03

🕵️Threat Intelligence

1
Wiz
CVE-2025-59060 Impact, Exploitability, and Mitigation Steps | Wiz