Description
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
Remediation
References
http://www.securityfocus.com/bid/94221
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2018-1000862 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-2231 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-10317 Vulnerability in maven package org.jvnet.hudson.plugins:sitemonitor
CVE-2017-1000424 Vulnerability in maven package org.webjars.npm:electron
CVE-2016-6812 Vulnerability in maven package org.apache.cxf:cxf-rt-transports-http