Description
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
Remediation
References
http://www.securityfocus.com/bid/95998
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2022-26112 Vulnerability in maven package org.apache.pinot:pinot-broker
CVE-2018-14042 Vulnerability in maven package org.webjars.npm:bootstrap
CVE-2020-9495 Vulnerability in maven package org.apache.archiva:archiva
CVE-2022-24814 Vulnerability in npm package directus
CVE-2018-8014 Vulnerability in maven package org.apache.tomcat:tomcat-catalina