Description
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
Remediation
References
http://www.securityfocus.com/bid/94221
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2023-22894 Vulnerability in npm package @strapi/strapi
CVE-2020-25711 Vulnerability in maven package org.infinispan:infinispan-server-rest
CVE-2021-25947 Vulnerability in npm package nestie
CVE-2022-23494 Vulnerability in npm package tinymce
CVE-2022-3971 Vulnerability in npm package matrix-appservice-irc