GHSA-89gw-cffj-mqg9
GitHub Security Advisory
Apache Ranger code execution vulnerability in policy expressions
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Affected Packages
Maven
org.apache.ranger:ranger
Affected versions:
2.3.0
(fixed in 2.4.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.