CRITICAL9.8
GHSA-c87w-642h-m97h
Apache Ranger has a Code Injection vulnerability
Quick fix
GHSA-c87w-642h-m97h — org.apache.ranger:ranger-plugins-common: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.8.0</version> for org.apache.ranger:ranger-plugins-commonDetails
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0.
Users are recommended to upgrade to version 2.8.0, which fixes this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.ranger:ranger-plugins-common
Introduced in:
0Fixed in: 2.8.0Fix
# pom.xml: bump <version>2.8.0</version> for org.apache.ranger:ranger-plugins-common