GHSA-g9gf-g5jq-9h3vCriticalCVSS 9.1
Apache Ranger UI vulnerable to Server Side Request Forgery
🔗 CVE IDs covered (1)
📋 Description
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
🎯 Affected products1
- maven/org.apache.ranger:ranger:>= 0.5.0, < 2.5.0
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2024-45479
- https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
- http://www.openwall.com/lists/oss-security/2025/01/21/4
- https://github.com/apache/ranger/commit/447658578decf33d2b68d872a32db59227dfef1b#diff-0cb27d5067c1eced82c6a8a755e6142d20c633820996701a1ca616345ea8b1ca
- https://github.com/advisories/GHSA-g9gf-g5jq-9h3v