VDB
Sign up
CRITICAL9.8

GHSA-c87w-642h-m97h

Apache Ranger has a Code Injection vulnerability

Quick fix

GHSA-c87w-642h-m97h — org.apache.ranger:ranger-plugins-common: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.8.0</version> for org.apache.ranger:ranger-plugins-common

Details

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0.

Users are recommended to upgrade to version 2.8.0, which fixes this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.ranger:ranger-plugins-common
Introduced in: 0Fixed in: 2.8.0
Fix# pom.xml: bump <version>2.8.0</version> for org.apache.ranger:ranger-plugins-common

References