Apache Ranger access Restriction Bypass Vulnerability (CVE-2015-0266)
Apache Ranger access Restriction Bypass Vulnerability (CVE-2015-0266)
Release date:
Updated on:
Affected Systems:
Apache Group Ranger 0.5.x <0.5.2
Description:
Bugtraq id: 76221
CVE (CAN) ID: CVE-2015-0266
Ranger is a comprehensive data security framework for implementing, monitoring, and managing Hadoop platforms.
Apache Ranger 0.5.x <0.5.0 version Policy Admin Tool has a security vulnerability. Directly access the module url. authenticated remote users can bypass the target access restriction.
<* Source: Jakub Kaluzny
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
This article permanently updates the link address: