Apache Ranger: code execution vulnerability in policy expressions
CVE-2022-45048
8.8HIGH
What is CVE-2022-45048?
Authenticated users with the necessary privileges in Apache Ranger can exploit a vulnerability by creating specific policies that trigger arbitrary code execution. This flaw affects version 2.3.0, with users urged to upgrade to version 2.4.0 to mitigate the risk. It is crucial for organizations using this software to perform timely updates and enhance their security posture.
Affected Version(s)
Apache Ranger 2.3.0