Apache Ranger Security Restriction Bypass Vulnerability (CVE-2016-0735)
Apache Ranger Security Restriction Bypass Vulnerability (CVE-2016-0735)
Release date:
Updated on:
Affected Systems:
Apache Group Ranger 0.5.x <0.5.2
Description:
CVE (CAN) ID: CVE-2016-0735
Ranger is a comprehensive data security framework for implementing, monitoring, and managing Hadoop platforms.
Apache Ranger 0.5.x <0.5.2 has a security vulnerability. The error handling resource layer exclusion policy allows authenticated remote users to bypass the upper-level resource layer access restrictions.
<* Source: Apache
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://ranger.apache.org/
Refer:
Http://mail-archives.apache.org/mod_mbox/ranger-dev/201603.mbox/%3CD31EE434.14B879%25vel%40apache.org%3E
This article permanently updates the link address: